Improper authentication in macOS - CVE-2025-24206
Published: April 29, 2025
Vulnerability identifier: #VU108021
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-24206
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to a state issue in AirPlay when handling authentication requests. A remote attacker on the local network can bypass authentication process and gain unauthorized access to the system.
Affected software
macOS
visionOS
iPadOS
tvOS
Apple iOS
visionOS
iPadOS
tvOS
Apple iOS
How to mitigate CVE-2025-24206
Install updates from vendor's website.
macOS - addressed in versions 15.4 24E248, 13.7.5 22H527, 14.7.5 23H527
visionOS - update to 2.4
iPadOS - addressed in versions 17.7.6, 18.4 22E240
tvOS - update to 18.4
Apple iOS - update to 18.4 22E240
visionOS - update to 2.4
iPadOS - addressed in versions 17.7.6, 18.4 22E240
tvOS - update to 18.4
Apple iOS - update to 18.4 22E240