Main
Vulnerability Database
Exploits
ID:11379 - Exploit for Missing authorization in macOS - CVE-2025-24271
ID:11379 - Exploit for Missing authorization in macOS - CVE-2025-24271
Published: May 9, 2025
Vulnerability identifier: #VU108022
Vulnerability risk: Medium
CVE-ID: CVE-2025-24271
CWE-ID: CWE-862
Exploitation vector: Adjecent network
Vulnerable software:
macOS
macOS
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to missing authorization checks in AirPlay. A remote non-authenticated attacker on the same network as a signed-in Mac can send it AirPlay commands without pairing.
Remediation
Install updates from vendor's website.