• Update your Apple Devices Wormable Zero-Click Remote Code Execution in AirPlay..

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Update your Apple Devices Wormable Zero-Click Remote Code Execution in AirPlay..

    Author
    Topic
    #2768639

    Wormable Zero-Click Remote Code Execution (RCE) in AirPlay / CarPlay Protocol Puts Apple & IoT Devices at Risk

    Oligo Security Research has discovered a new set of vulnerabilities in Apple’s AirPlay Protocol and the AirPlay Software Development Kit (SDK), which is used by third-party vendors to integrate AirPlay into third-party devices.

    The vulnerabilities enable an array of attack vectors and outcomes, including:

    Zero-Click RCE
    One-Click RCE
    Access control list (ACL) and user interaction bypass
    Local Arbitrary File Read
    Sensitive information disclosure
    Man-in-the-middle (MITM) attacks
    Denial of service (DoS)..

    Apple and Oligo have worked together to thoroughly identify and address the vulnerabilities with the goal of protecting end-users. Apple has released its latest versions of software to address the vulnerabilities and has allowed time for those devices to be updated…

    The Oligo Security research team reported 23 vulnerabilities to Apple. All of the flaws have ultimately been fixed..

    tvOS 18.4
    iOS 18.4
    iPadOS 18.4
    iPadOS 17.7.6
    macOS Sequoia 15.4
    visionOS 2.4
    macOS Sonoma 14.7.5
    macOS Ventura 13.7.5..

    Viewing 0 reply threads
    Author
    Replies
    • #2768723

      already updated my iphone SE 2nd gen device to iOS 18.4.1 more than a week ago

      1 user thanked author for this post.
    Viewing 0 reply threads
    Reply To: Update your Apple Devices Wormable Zero-Click Remote Code Execution in AirPlay..

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: