#VU108022 Missing authorization in macOS - CVE-2025-24271


| Updated: 2025-05-09

Vulnerability identifier: #VU108022

Vulnerability risk: Medium

CVSSv4.0: 2.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/U:Green]

CVE-ID: CVE-2025-24271

CWE-ID: CWE-862

Exploitation vector: Local network

Exploit availability: Yes

Vulnerable software:
macOS
Operating systems & Components / Operating system

Vendor: Apple Inc.

Description

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to missing authorization checks in AirPlay. A remote non-authenticated attacker on the same network as a signed-in Mac can send it AirPlay commands without pairing.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

macOS: 15.0 24A335, 15.0.1 24A348, 15.1 24B83, 15.1.1 24B91, 15.1.1 24B2091, 15.2 24C101, 15.3 24D60, 15.3.1 24D70, 15.3.2 24D81, 15.3.2 24D2082


External links
https://support.apple.com/en-us/122373


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.


Latest bulletins with this vulnerability