Active Exploitation
Attackers on the same Wi-Fi network send crafted AirPlay packets exploiting bugs like use-after-free (e.g., CVE-2025-24252) or buffer overflows in the protocol/SDK.
This enables zero-click remote code execution—no interaction needed—letting them install malware, read files, or steal data on vulnerable devices.
It's wormable, so it can spread across the network. Apple patched it fully in iOS 18.4+ (March 2025). If updated, you're protected. Check Settings > General > Software Update.
Post summary
CVE‑2025‑24252 is actively exploited via zero‑click, wormable AirPlay packets, enabling remote code execution on vulnerable devices; Apple has fixed the issue in iOS 18.4+.