CVE-2025-30422

A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.
References
Link Resource
https://support.apple.com/en-us/122403 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:airplay_audio_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:airplay_video_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:carplay_communication_plug-in:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:19

Type Values Removed Values Added
Summary (en) A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1, AirPlay video SDK 3.6.0.126, CarPlay Communication Plug-in R18.1. An attacker on the local network may cause an unexpected app termination. (en) A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.

12 May 2025, 19:41

Type Values Removed Values Added
References () https://support.apple.com/en-us/122403 - () https://support.apple.com/en-us/122403 - Vendor Advisory
CPE cpe:2.3:a:apple:airplay_audio_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:airplay_video_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:carplay_communication_plug-in:*:*:*:*:*:*:*:*
First Time Apple airplay Video Software Development Kit
Apple airplay Audio Software Development Kit
Apple
Apple carplay Communication Plug-in

02 May 2025, 13:53

Type Values Removed Values Added
Summary
  • (es) Se solucionó un desbordamiento de búfer mejorando la validación de entrada. Este problema se solucionó en el SDK de audio de AirPlay 2.7.1, el SDK de vídeo de AirPlay 3.6.0.126 y el complemento de comunicación de CarPlay R18.1. Un atacante en la red local podría provocar el cierre inesperado de la aplicación.

01 May 2025, 14:15

Type Values Removed Values Added
CWE CWE-120
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

30 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-30 21:15

Updated : 2026-04-02 19:19


NVD link : CVE-2025-30422

Mitre link : CVE-2025-30422

CVE.ORG link : CVE-2025-30422


JSON object : View

Products Affected

apple

  • airplay_video_software_development_kit
  • airplay_audio_software_development_kit
  • carplay_communication_plug-in
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')