SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2025-24132

An attacker on the local network may cause an unexpected app termination.

MEDIUM 6.5EPSS 3.15%

Does this matter?

Lower severity and a low EPSS score (3.15%). Track it; it rarely justifies an emergency change on its own.

Description

The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
3.15% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
apple/airplay audio software development kit · apple/airplay video software development kit · apple/carplay communication plug-in
Source
product-security@apple.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.