Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

    January 13, 2026

    Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

    January 13, 2026

    Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

    January 13, 2026
    Facebook X (Twitter) Instagram
    Tuesday, January 13
    Facebook X (Twitter) Instagram YouTube Mastodon Tumblr Bluesky LinkedIn Threads
    ToolcomeToolcome
    • Technology & Startups

      Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

      January 13, 2026

      Urevo SpaceWalk 5L Walking Pad Review: Compact and Affordable

      January 13, 2026

      Board Review: Tabletop Video Games With Physical Pieces

      January 13, 2026

      Atonemo Streamplayer Review: Make Old Speakers New Again

      January 13, 2026

      What to Do If ICE Invades Your Neighborhood

      January 13, 2026
    • Science & Education

      Hubble Nets Menagerie of Young Stellar Objects

      January 13, 2026

      Ötzi the Iceman mummy carried a high-risk strain of HPV, research finds

      January 13, 2026

      Can you eat too much protein?

      January 13, 2026

      NASA’s Webb Delivers Unprecedented Look Into Heart of Circinus Galaxy

      January 13, 2026

      Backcountry is blowing out hiking bags, backpacks, and luggage for up to 65% off during this clearance sale

      January 13, 2026
    • Mobile Phones

      Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

      January 13, 2026

      Motorola expands Android 16 beta program to 8 more devices

      January 13, 2026

      Motorola Introduces Moto Pen Ultra for Foldables and Moto Tag 2 Item Tracker

      January 13, 2026

      OnePlus Nord CE 5 Update Adds Video Editing Tools and January Security Patch

      January 13, 2026

      Vivo rolls out OriginOS 6 (Android 16) update to Vivo V40

      January 13, 2026
    • Gadgets

      Star Wars Outlaws developer Massive Entertainment and Ubisoft Stockholm face layoffs

      January 13, 2026

      Insta360 releases AI-powered follow-up to its Link webcams

      January 13, 2026

      Proton’s Lumo AI chatbot now has an encrypted space for your projects

      January 13, 2026

      The best streaming devices for 2026

      January 13, 2026

      UK regulator Ofcom opens a formal investigation into X over CSAM scandal

      January 13, 2026
    • Gaming

      Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

      January 13, 2026

      ASUS ROG Xbox Ally (2025 Ryzen Z2 A) Just Hit Its Lowest Price Ever With 3 Months of Game Pass Included

      January 13, 2026

      Samsung Goes All-In on Galaxy S25 Ultra Clearance at a Record Low as the New S26 Launch Approaches

      January 13, 2026

      This Great Switch 2 Handheld Controller Is On Sale For New Best Price At Amazon

      January 13, 2026

      Google Pixel 9a Drops to All-Time Low to Compete With Samsung Galaxy S25 Deals, Now the Cheapest Gemini-Powered Smartphone

      January 13, 2026
    • Cars

      Beyond Speed: A Deep Dive into the 6 Safety Features That Could Save Your Supercar in 2026

      January 13, 2026

      A Commercial Truck Caused a Hit-and-Run: Who Pays for the Damage?

      January 13, 2026

      Risk and reward: what driving teaches about smart decisions

      January 13, 2026

      How It’s Played Online on GameZone

      January 12, 2026

      How Dubai Became the Supercar Capital of the World

      January 12, 2026
    • PC Accessories

      A Kilowatt PSU Is So 2025, The Seasonic Prime PX-2200 Is The Future

      January 12, 2026

      CES 2026: The Good, Bad And Ugly

      January 12, 2026

      Hands-On With Samsung Galaxy Z TriFold: An Impressive New Take On Foldables

      January 11, 2026

      Edifier’s Funky Portable ES300 Wireless Speaker

      January 9, 2026

      Testing All The Features of AMD’s FSR Redstone

      January 9, 2026
    ToolcomeToolcome
    Home»PC Accessories»Urgent Apple AirPlay Security Alert Sounds For Billions Of Devices
    PC Accessories

    Urgent Apple AirPlay Security Alert Sounds For Billions Of Devices

    November 2, 2025No Comments5 Mins Read1 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    airplay vulnerability

    Do you use AirPlay to send videos from an iPhone, iPad, or Mac to a television or play music through a smart speaker? Then friends, you are in for a treat. Thanks to a vulnerability in not just Apple’s operating system, but the ecosystem-wide AirPlay software development kit (SDK), over two billion devices are vulnerable to a zero-click remote code execution bug. And it only gets worse from there. 

    The series of vulnerabilities in the AirPlay SDK, collectively dubbed AirBorne, is a rare one in that it doesn’t require any social engineering or user manipulation for an attacker to exploit. All that needs to happen is for the bad actor to be in the general vicinity of a device that implements AirPlay and send a well-crafted message to a vulnerable device, and they can run any code their heart desires on that device. The folks over at Oligo Security discovered the bugs and produced their own proof-of-concept that allowed them to take full control as root on a Mac through Apple Music’s AirPlay implementation. 

    airplay devices
    If your device advertises AirPlay, make sure it’s updated.

    There are actually a host of vulnerabilities that were all wrapped together to make potential exploits so scary. First of all, they can bypass the Access Control List (ACL) that allows an unauthenticated user to take control of a device. And of course, from there you can say goodbye to your privacy for personal data on the device as encryption keys and passwords are available to a root user. And because it doesn’t take any user intervention, the issue can propagate to other AirPlay devices like wildfire, which means exploits could potentially be wormable. 

    Devices can get to that state through remote code execution vulnerabilities. A Use After Free bug would allow a bad actor to point to a data address that had supposedly been freed up and reuse the data there. If the data didn’t have its address randomized properly, then a hacker could predict where a piece of data would be and write something else to that location. Then through an approach called “type confusion,” the next time it’s picked up, the data doesn’t conform to the correct type and you can wind up with stack-based overflows and the gates are open. 

    apple mac studio m4 max 2025 review 14
    Your Macs are covered, but the AirBorne vulnerability goes farther than that. 

    Fortunately for those with Apple devices, the software updates to fix this vulnerability are already out in the wild. Devices running iOS or iPadOS 18.4, macOS 15.4, watchOS 11.3, and visionOS 2.3 or later all have the fixes required to address the problem. So our iPhone 16 Pro and M4 Max Mac Studio are covered, and your iDevices probably are, too. Additionally, Apple has released patches for iPadOS 17 and macOS going back to version 13. And the AirPlay SDK has already been updated and distributed to hardware makers, as well.

    But just search HotHardware for the term “AirPlay” and you’ll start to get a feel for the depth and breadth of the issue. According to Apple in January of this year, approximately 2.35 billion devices in the world implement AirPlay. Obviously that includes all the iPhones, iPads, and Macs that users have bought from Cupertino, but it also includes things like smart TVs, smart speakers, home theater receivers, automotive CarPlay-compatible devices (especially those with wireless CarPlay), and more. AirPlay is super convenient for Apple users, because it allows them to talk to devices outside of their ecosystem. 

    insignia tv deal
    If you took advantage of recent deals, make sure your third-party devices get updated

    An SDK vulnerability is an especially big deal because no self-respecting hardware manufacturer is going to implement the AirPlay protocol by hand. This author has four TVs in the house, all of which support AirPlay, as well as a home theater receiver and two AirPlay-compatible sound bars in different rooms. All seven of those non-Apple devices are theoretically vulnerable unless a firmware update has been released or I go through each and turn AirPlay off. 

    The saving grace even for third-party devices is that it’s very unlikely that an exploit of any value could be released universally for all AirPlay devices. Each IoT device with AirPlay could have its own hardware configuration including processor, memory, storage, and OS. At best, you might see (for example) something that targets unpatched LG WebOS devices or Samsung Tizen devices, but even that could be a stretch; it might come down to targeting specific models or specific firmware versions. Still, the fact this has existed for so long is a pretty noteworthy event. 

    The real problem is that third party manufacturers have to implement the new AirPlay SDK and release updates for their devices. There are likely hundreds of millions of devices in the wild that offer AirPlay yet have reached the end of their software development lifecycle. So you’ll want to check with the manufacturer of each device to ensure that the latest firmware has been applied, and that it includes the fixes disclosed by Oligo. And if there is no update, your best bet is to disable AirPlay on those devices entirely. 

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    mehedihasan9992
    • Website

    Related Posts

    A Kilowatt PSU Is So 2025, The Seasonic Prime PX-2200 Is The Future

    January 12, 2026

    CES 2026: The Good, Bad And Ugly

    January 12, 2026

    Hands-On With Samsung Galaxy Z TriFold: An Impressive New Take On Foldables

    January 11, 2026

    Edifier’s Funky Portable ES300 Wireless Speaker

    January 9, 2026

    Testing All The Features of AMD’s FSR Redstone

    January 9, 2026

    WiFi Gets Moar Power – PC Perspective

    January 9, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Steam and Valve’s online games are down

    December 24, 2025129 Views

    773,000-year-old fossils found in Casablanca may be earliest common ancestor of modern humans and Neanderthals

    January 8, 202695 Views

    Black Friday Disney+, Hulu and ESPN streaming deal: Up to 44% off

    November 30, 202542 Views
    Don't Miss

    Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

    January 13, 2026

    Reid Hoffman doesn’t do much in half measures. He cofounded LinkedIn, of course, and helped…

    Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

    January 13, 2026

    Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

    January 13, 2026

    Hubble Nets Menagerie of Young Stellar Objects

    January 13, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    8.9

    Review: Dell’s New Tablet PC Can Survive -20f And Drops

    January 15, 2021

    Review: Kia EV6 2022 The Best Electric Vehicle Ever?

    January 14, 2021
    72

    Review: Animation Software Business Share, Market Size and Growth

    January 14, 2021
    Most Popular

    Steam and Valve’s online games are down

    December 24, 2025129 Views

    773,000-year-old fossils found in Casablanca may be earliest common ancestor of modern humans and Neanderthals

    January 8, 202695 Views

    Black Friday Disney+, Hulu and ESPN streaming deal: Up to 44% off

    November 30, 202542 Views
    Our Picks

    Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

    January 13, 2026

    Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

    January 13, 2026

    Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

    January 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Toolcome
    Facebook X (Twitter) Instagram YouTube Mastodon Bluesky
    • Home
    • Technology
    • Gaming
    • Mobile Phones
    • Cars
    • PC Accessories
    © 2026 Tolcome.

    Type above and press Enter to search. Press Esc to cancel.