JAKARTA - Cybersecurity researchers discovered new vulnerabilities on Apple's AirPlay, dubbed AirBorne. This vulnerability has the potential to open the door to cyberattacks on millions of devices around the world.

In its findings, Kaspersky researchers revealed that the bug could be used individually or in combination to carry out wireless attacks on various hardware that support AirPlay.

For information, AirPlay is a series of protocols developed by Apple which are used in various devices, ranging from the iPhone, MacBook, to smart loudspeakers and car infotainment units.

The researchers managed to find a total of 23 vulnerabilities, which after review resulted in 17 CVE entries being registered. These vulnerabilities allow various attack scenarios, including clickless remote code execution (zero-click RCE), man-in-the-middle (MitM) attacks, denial of service (DoS), to sensitive data theft.

However, the most dangerous AirBorne vulnerability is the combination of CVE-2025-24252 with CVE-2025-24206, which can be used to attack macOS devices and activate remote code execution without user interaction, or simply by being on the same Wi-Fi network.

In the test, the researchers even succeeded in replacing the Apple Music application with malicious payloads without the user's knowledge.

Finally, the researchers explored and tested several scenarios of attacks on car infotainment units via CarPlay. Once again, they were able to achieve the execution of the arbitrary code without car owners doing anything.

This type of attack can usually be used for perpetrators to track a person's movements or eavesdrop on their conversations in the car.


The English, Chinese, Japanese, Arabic, and French versions are automatically generated by the AI. So there may still be inaccuracies in translating, please always see Indonesian as our main language. (system supported by DigitalSiber.id)

Add VOI as a Preferred Source
Follow VOI news updates across Google.
+