CVE-2025-24132

The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.
References
Link Resource
https://support.apple.com/en-us/122403 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:airplay_audio_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:airplay_video_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:carplay_communication_plug-in:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:19

Type Values Removed Values Added
Summary (en) The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1, AirPlay video SDK 3.6.0.126, CarPlay Communication Plug-in R18.1. An attacker on the local network may cause an unexpected app termination. (en) The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.

12 May 2025, 19:41

Type Values Removed Values Added
First Time Apple airplay Video Software Development Kit
Apple airplay Audio Software Development Kit
Apple
Apple carplay Communication Plug-in
References () https://support.apple.com/en-us/122403 - () https://support.apple.com/en-us/122403 - Vendor Advisory
CPE cpe:2.3:a:apple:airplay_audio_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:airplay_video_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:carplay_communication_plug-in:*:*:*:*:*:*:*:*

02 May 2025, 13:53

Type Values Removed Values Added
Summary
  • (es) El problema se solucionó mejorando la gestión de la memoria. Este problema se solucionó en el SDK de audio de AirPlay 2.7.1, el SDK de vídeo de AirPlay 3.6.0.126 y el complemento de comunicación de CarPlay R18.1. Un atacante en la red local podría provocar el cierre inesperado de la aplicación.

01 May 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-119

30 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-30 21:15

Updated : 2026-04-02 19:19


NVD link : CVE-2025-24132

Mitre link : CVE-2025-24132

CVE.ORG link : CVE-2025-24132


JSON object : View

Products Affected

apple

  • airplay_video_software_development_kit
  • airplay_audio_software_development_kit
  • carplay_communication_plug-in
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer