AirBorne: Wormable Zero-Click RCE in Apple AirPlay Puts Billions of Devices at Risk | Oligo Security | Oligo Security
TL;DROligo Security Research has discovered a new set of vulnerabilities in Apple’s AirPlay Protocol and the AirPlay Software Development Kit (SDK), which is used by third-party vendors to integrate AirPlay into third-party devices.The vulnerabilities enable an array of attack vectors and outcomes, including:Zero-Click RCEOne-Click RCEAccess control list (ACL) and user interaction bypassLocal Arbitrary File ReadSensitive information disclosureMan-in-the-middle (MITM) attacksDenial of service (Do...
Read more at oligo.security