Buffer Overflow Vulnerability in Apple AirPlay and CarPlay Products
CVE-2025-30422
6.5MEDIUM
Key Information:
- Vendor
- Apple
- Vendor
- CVE Published:
- 30 April 2025
Summary
A buffer overflow vulnerability has been identified in Apple’s AirPlay and CarPlay products due to inadequate input validation. An attacker on the local network could exploit this flaw, potentially leading to unexpected app terminations and causing disruptions in service. The vulnerability has been addressed in the latest versions of the AirPlay audio SDK, AirPlay video SDK, and CarPlay Communication Plug-in, with updates aimed at enhancing security and usability.
Affected Version(s)
AirPlay audio SDK < 2.7.1
AirPlay video SDK < 3.6.0.126
CarPlay Communication Plug-in < unspecified
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published