SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2025-30422

A buffer overflow was addressed with improved input validation.

MEDIUM 6.5EPSS 0.67%

Does this matter?

Lower severity and a low EPSS score (0.67%). Track it; it rarely justifies an emergency change on its own.

Description

A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.67% probability · 50th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
apple/airplay audio software development kit · apple/airplay video software development kit · apple/carplay communication plug-in
Source
product-security@apple.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.