Buffer Overflow Vulnerability in Apple AirPlay and CarPlay Products
CVE-2025-30422

6.5MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
30 April 2025

Summary

A buffer overflow vulnerability has been identified in Apple’s AirPlay and CarPlay products due to inadequate input validation. An attacker on the local network could exploit this flaw, potentially leading to unexpected app terminations and causing disruptions in service. The vulnerability has been addressed in the latest versions of the AirPlay audio SDK, AirPlay video SDK, and CarPlay Communication Plug-in, with updates aimed at enhancing security and usability.

Affected Version(s)

AirPlay audio SDK < 2.7.1

AirPlay video SDK < 3.6.0.126

CarPlay Communication Plug-in < unspecified

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-30422 : Buffer Overflow Vulnerability in Apple AirPlay and CarPlay Products | SecurityVulnerability.io