Apple 及物联网设备面临风险 | 空中传播:AirPlay 协议中的零点击蠕虫式远程代码执行漏洞

安全动态   ·   发表于 2025-05-06 20:54:05   ·   安全动态每天看
<h1 data-lake-id="aMUaG" id="aMUaG"><span data-lake-id="u0823030c" id="u0823030c" style="color: rgb(51, 51, 51)">空中传播：AirPlay 协议中的零点击蠕虫式远程代码执行（RCE）漏洞让 Apple 及物联网设备面临风险</span></h1><h2 data-lake-id="jt4HZ" id="jt4HZ"><strong><span data-lake-id="uf85514ca" id="uf85514ca" style="color: rgb(51, 51, 51)">概要</span></strong></h2><p data-lake-id="uc3cd9e44" id="uc3cd9e44"><span data-lake-id="udc15c3b7" id="udc15c3b7" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">Oligo 安全研究团队发现了 Apple 的 AirPlay 协议及其软件开发工具包（SDK）中的一组新漏洞，后者被第三方厂商用于将 AirPlay 集成进自家设备中。</span></p><p data-lake-id="u04c9e5e7" id="u04c9e5e7"><span data-lake-id="u81a090d6" id="u81a090d6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">这些漏洞可被利用实现多种攻击方式和结果，包括：</span></p><ul list="u871961a9"><li fid="u6b67d312" data-lake-id="u47da7ca4" id="u47da7ca4"><span data-lake-id="uc1e4b8f9" id="uc1e4b8f9" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">零点击远程代码执行（Zero-Click RCE）</span></li><li fid="u6b67d312" data-lake-id="u5026ad79" id="u5026ad79"><span data-lake-id="ue204505f" id="ue204505f" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">单点击远程代码执行（One-Click RCE）</span></li><li fid="u6b67d312" data-lake-id="ubd80e270" id="ubd80e270"><span data-lake-id="uab5818f7" id="uab5818f7" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">绕过访问控制列表（ACL）和用户交互</span></li><li fid="u6b67d312" data-lake-id="ue22b6b08" id="ue22b6b08"><span data-lake-id="ubbeb37dc" id="ubbeb37dc" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">本地任意文件读取</span></li><li fid="u6b67d312" data-lake-id="u54bfab09" id="u54bfab09"><span data-lake-id="u9e3a57a9" id="u9e3a57a9" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">敏感信息泄露</span></li><li fid="u6b67d312" data-lake-id="udd355019" id="udd355019"><span data-lake-id="u80e9459d" id="u80e9459d" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">中间人攻击（MITM）</span></li><li fid="u6b67d312" data-lake-id="u28d5e1a8" id="u28d5e1a8"><span data-lake-id="u1a7a565c" id="u1a7a565c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">拒绝服务攻击（DoS）</span></li></ul><p data-lake-id="uf1126004" id="uf1126004"><span data-lake-id="u6eef4d67" id="u6eef4d67" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">攻击者可以将这些漏洞进行组合利用，从而可能控制支持 AirPlay 的设备，包括 Apple 自家设备以及使用 AirPlay SDK 的第三方设备。</span></p><p data-lake-id="u51d91755" id="u51d91755"><span data-lake-id="uc80aba4e" id="uc80aba4e" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">Oligo 将这些漏洞及其所启用的攻击方式命名为 “AirBorne”，因为相关攻击可通过无线网络或点对点连接传播，并允许攻击者完全控制设备，并将该访问权限作为进一步攻击的跳板。</span></p><p data-lake-id="u99a70437" id="u99a70437"><span data-lake-id="u3d4526ea" id="u3d4526ea" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">Oligo 证明其中两个漏洞（CVE-2025-24252 和 CVE-2025-24132）可被</span><strong><span data-lake-id="ucbca5f5a" id="ucbca5f5a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">武器化为可蠕虫式的零点击 RCE 漏洞</span></strong><span data-lake-id="uf158a688" id="uf158a688" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">。这意味着攻击者可以接管启用 AirPlay 的设备，部署会传播的恶意软件，并感染任何该设备连接的本地网络中的其他设备。这可能导致间谍活动、勒索软件、供应链攻击等高级攻击的投递。</span></p><p data-lake-id="ufb6b33c6" id="ufb6b33c6"><span data-lake-id="u22494ce3" id="u22494ce3" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">由于 AirPlay 是 Apple 设备（如 Mac、iPhone、iPad、Apple TV 等）和部分第三方设备的关键组件，这类漏洞的影响范围可能非常广泛。</span></p><p data-lake-id="u722446f8" id="u722446f8"><span data-lake-id="u378ba8eb" id="u378ba8eb" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">一些数据参考：</span></p><ul list="u18fa440e"><li fid="u6c5c84a3" data-lake-id="u45ff1b6d" id="u45ff1b6d"><span data-lake-id="u750b1995" id="u750b1995" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">虽然并非所有 Apple 设备都易受 AirBorne 攻击，但 Apple 于 2025 年 1 月表示其全球活跃设备已达 23.5 亿台。</span></li><li fid="u6c5c84a3" data-lake-id="uaadbe47e" id="uaadbe47e"><span data-lake-id="uad738426" id="uad738426" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">2018 年 Apple 表示其 macOS 活跃用户已超 1 亿。</span></li><li fid="u6c5c84a3" data-lake-id="u506a7bac" id="u506a7bac"><span data-lake-id="u2da1f67b" id="u2da1f67b" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">iPhone、Apple TV、Vision Pro 等设备也受不同 AirBorne 漏洞影响，其中 iPhone 需在设置中手动开启 AirPlay 接收器功能。</span></li><li fid="u6c5c84a3" data-lake-id="ub149f92d" id="ub149f92d"><span data-lake-id="u1f872d3a" id="u1f872d3a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">支持 AirPlay 的第三方音频设备数量估计达数千万。</span></li><li fid="u6c5c84a3" data-lake-id="u6635c6ae" id="u6635c6ae"><span data-lake-id="u6621b3b6" id="u6621b3b6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">虽然支持 CarPlay 的具体设备数不详，但其已在 800 多款车型中广泛使用。</span></li></ul><p data-lake-id="u0fdf9035" id="u0fdf9035"><span data-lake-id="u21905fb4" id="u21905fb4" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">Apple 与 Oligo 已合作识别并修复这些漏洞，目标是保护终端用户。Apple 已发布最新软件版本修复漏洞，并留出时间供用户更新。在负责任的漏洞披露过程中，Oligo 向 Apple 提供了漏洞相关的文档、流程与代码。</span></p><p data-lake-id="u41d014bd" id="u41d014bd"><span data-lake-id="uf500e98c" id="uf500e98c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">Oligo 共向 Apple 披露了 23 个漏洞，最终发布了 17 个 CVE 编号。完整的 CVE 列表及其所启用的攻击场景详见下文。</span></p><card type="block" name="hr" value="data:%7B%22id%22%3A%22J9UC5%22%7D"></card><h2 data-lake-id="T0x5M" id="T0x5M"><strong><span data-lake-id="u65b07fa3" id="u65b07fa3" style="color: rgb(51, 51, 51)">攻击类型</span></strong></h2><p data-lake-id="uf6c79f7e" id="uf6c79f7e"><span data-lake-id="ude7633c6" id="ude7633c6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">Oligo 发现的这些漏洞，无论是单独使用还是组合利用，都可以实现多种攻击向量，包括</span><a href="https://www.oligo.security/academy/remote-code-execution-rce-how-it-works-and-8-defensive-strategies" target="_blank" data-lake-id="uc39090f9" id="uc39090f9"><span data-lake-id="u2318b418" id="u2318b418">远程代码执行（RCE）</span></a><span data-lake-id="u97338091" id="u97338091" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">、访问控制列表绕过、用户交互绕过、本地任意文件读取、敏感信息泄露、中间人攻击（MITM）、拒绝服务（DoS）攻击。</span></p><p data-lake-id="uafe5d12d" id="uafe5d12d"><span data-lake-id="u5522200e" id="u5522200e" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">本文重点分析基于 MacOS、AirPlay SDK 和 CarPlay 设备的 RCE 攻击。在未来的文章中，Oligo 可能还会分析其他设备及攻击类型。</span></p><h3 data-lake-id="SeoGD" id="SeoGD"><strong><span data-lake-id="u6a8292db" id="u6a8292db" style="color: rgb(51, 51, 51)">远程代码执行（RCE）攻击</span></strong></h3><p data-lake-id="ue2a98b56" id="ue2a98b56"><span data-lake-id="u7e9e5806" id="u7e9e5806" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">利用 AirBorne，攻击者可以在特定条件下对易受攻击的设备实现远程代码执行，这些条件包括 Apple 或第三方设备的设置，以及用户偏好。</span></p><p data-lake-id="uaeae7f05" id="uaeae7f05"><span data-lake-id="uf6e74479" id="uf6e74479" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">以下是根据不同配置下可能实现的 RCE 攻击示例：</span></p><h4 data-lake-id="mFN8I" id="mFN8I"><strong><span data-lake-id="u5fbc329f" id="u5fbc329f" style="color: rgb(51, 51, 51)">MacOS – 零点击 RCE</span></strong></h4><p data-lake-id="ua8f9000e" id="ua8f9000e"><strong><span data-lake-id="uddba1aff" id="uddba1aff" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24252</span></strong><span data-lake-id="u179e9f6a" id="u179e9f6a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 是一个使用后释放（Use-After-Free, UAF）漏洞，可被利用为标准 UAF 攻击，也可以被操控为“任意释放”，使攻击者能在 macOS 设备上远程执行代码。</span></p><p data-lake-id="u11530e7e" id="u11530e7e"><span data-lake-id="u428b609c" id="u428b609c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">当该漏洞与 </span><strong><span data-lake-id="u3d652b38" id="u3d652b38" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24206</span></strong><span data-lake-id="uec89d3a7" id="uec89d3a7" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">（用户交互绕过）组合使用时，攻击者可对与其处于同一网络中的 macOS 设备实现零点击 RCE，只要该设备开启了 AirPlay 接收器并设置为“同一网络中的任何人”或“所有人”。</span></p><p data-lake-id="u1a6cd696" id="u1a6cd696"><span data-lake-id="u93c8f8cf" id="u93c8f8cf" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">在该配置下，漏洞具备可蠕虫化特性，即攻击路径可以从一台设备自动传播到另一台设备，无需人工干预。</span></p><p data-lake-id="u2b53b89f" id="u2b53b89f"><span data-lake-id="u8dcc130e" id="u8dcc130e" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">一种潜在场景：受害设备在公共 WiFi 下被入侵，之后连接到公司网络，从而为攻击者提供横向移动的路径，接管更多设备。</span></p><p data-lake-id="ue1494650" id="ue1494650"><span data-lake-id="ucc5fe5e5" id="ucc5fe5e5" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">以下视频展示了我们“写入任意地址”的原语，实时覆盖音乐应用。我们刻意增加了一个点击动作来启动应用，以便更清楚地展示效果。由于我们的原语可以覆盖任意内存地址，因此无需打开应用即可实现多种利用方式。</span></p><p data-lake-id="u4be292f5" id="u4be292f5"><span data-lake-id="ua9d57c2f" id="ua9d57c2f" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">利用过程，漏洞利用视频链接：</span><a href="https://www.youtube.com/embed/ZmOvRLBL3Ys?si=6F6wvPcPcLeDx9pb" target="_blank" data-lake-id="u023c4dc8" id="u023c4dc8"><span data-lake-id="uba126141" id="uba126141">https://www.youtube.com/embed/ZmOvRLBL3Ys?si=6F6wvPcPcLeDx9pb</span></a></p><card type="block" name="hr" value="data:%7B%22id%22%3A%22GFAns%22%7D"></card><h4 data-lake-id="zhqmP" id="zhqmP"><strong><span data-lake-id="u2b89b28b" id="u2b89b28b" style="color: rgb(51, 51, 51)">MacOS – 单点击 RCE</span></strong></h4><p data-lake-id="u9cf44b2a" id="u9cf44b2a"><strong><span data-lake-id="u745bab09" id="u745bab09" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24271</span></strong><span data-lake-id="u9fb4fccb" id="u9fb4fccb" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 是一个访问控制列表（ACL）漏洞，允许攻击者在未配对的情况下向目标设备发送 AirPlay 命令。当该漏洞与 </span><strong><span data-lake-id="u9193e33a" id="u9193e33a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24137</span></strong><span data-lake-id="u355622a1" id="u355622a1" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 组合使用时，可对配置为“当前用户”的 macOS 设备实现单点击 RCE，前提是设备与攻击者处于同一网络，并开启了 AirPlay 接收器。</span></p><p data-lake-id="ua3cc1b62" id="ua3cc1b62"><strong><span data-lake-id="u3469bb34" id="u3469bb34" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">注意：</span></strong><span data-lake-id="udf0e969c" id="udf0e969c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24137 已由 Apple 于 2025 年 1 月 27 日在 macOS Sequoia 15.3 中修复：</span></p><p data-lake-id="u6cd8c100" id="u6cd8c100"><card type="inline" name="image" value="data:%7B%22src%22%3A%22https%3A%2F%2Fcdn.prod.website-files.com%2F63e8dd453f71270c6845992b%2F6810a4ac696a37cdefa163cf_AD_4nXdpDLR8pzCQhOVdBBbKfm9AI167mlAVEJt_aZacAQ1l_7eC1674zMDCuD0wnz36FZeX3HLRRoWbpzmUEZRsdNNTgaQqkfyh3hde4p48jrunoVzq1VblbbkgPT_yDrTpxEUBBBuuSg.png%22%2C%22originalType%22%3A%22binary%22%2C%22linkTarget%22%3A%22_blank%22%2C%22from%22%3A%22url%22%2C%22originWidth%22%3A818%2C%22originHeight%22%3A200%2C%22ratio%22%3A1%2C%22status%22%3A%22done%22%2C%22style%22%3A%22none%22%2C%22showTitle%22%3Afalse%2C%22title%22%3A%22%22%2C%22rotation%22%3A0%2C%22crop%22%3A%5B0%2C0%2C1%2C1%5D%2C%22id%22%3A%22AzjKy%22%2C%22margin%22%3A%7B%22top%22%3Atrue%2C%22bottom%22%3Atrue%7D%7D" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"></card></p><p data-lake-id="u208d140d" id="u208d140d"><strong><span data-lake-id="uf4cb7d6f" id="uf4cb7d6f" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">AirPlay SDK - 扬声器与接收器 - 零点击远程代码执行（Zero-Click RCE）</span></strong></p><p data-lake-id="u5f6858ab" id="u5f6858ab"><strong><span data-lake-id="u221ca91e" id="u221ca91e" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24132</span></strong><span data-lake-id="u017f3622" id="u017f3622" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 是一个基于堆栈的缓冲区溢出漏洞。该漏洞允许攻击者在使用 AirPlay SDK 的扬声器和接收器设备上实现零点击远程代码执行（RCE）。无论设备处于何种配置状态，该漏洞都可被利用，从而在完全无需用户交互的情况下发动攻击。</span></p><p data-lake-id="u2ecb879b" id="u2ecb879b"><span data-lake-id="u1944705e" id="u1944705e" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">在这种情况下，漏洞可被用于构造“蠕虫式”攻击路径，使攻击从一个设备自动传播至另一个设备。</span></p><p data-lake-id="u0640d699" id="u0640d699"><span data-lake-id="u93033a75" id="u93033a75" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">成功攻击的结果可能包括一些“轻松”的操作，例如在设备上显示图像或播放音乐，也可能包括更为严重的行为，例如利用设备的麦克风监听附近的对话——比如在一个高规格会议室中窃听。</span></p><p data-lake-id="u4d4bfc26" id="u4d4bfc26"><span data-lake-id="ua10a7102" id="ua10a7102" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">利用过程，youtube上的视频演示链接：</span><a href="https://www.youtube.com/embed/vcs5G4JWab8?si=kgz3r_sZrbiiJ07e" target="_blank" data-lake-id="ua1c986f9" id="ua1c986f9"><span data-lake-id="uc62f717e" id="uc62f717e">https://www.youtube.com/embed/vcs5G4JWab8?si=kgz3r_sZrbiiJ07e</span></a></p><p data-lake-id="ub31c306a" id="ub31c306a"><strong><span data-lake-id="u49a48bdd" id="u49a48bdd" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CarPlay 设备 - 零点击与单点击远程代码执行（RCE）</span></strong></p><p data-lake-id="u33eb1f7a" id="u33eb1f7a"><strong><span data-lake-id="u5a9e2aad" id="u5a9e2aad" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24132</span></strong><span data-lake-id="u67a14f9a" id="u67a14f9a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 是一个基于堆栈的缓冲区溢出漏洞，同样适用于 CarPlay 设备。在特定条件下，该漏洞可实现零点击 RCE。攻击可能带来的结果包括：通过图像显示或播放音频分散驾驶员注意力，甚至执行更恶意的行为，如窃听车内对话或跟踪车辆位置。</span></p><p data-lake-id="uaa44d2db" id="uaa44d2db"><span data-lake-id="u9c0abbde" id="u9c0abbde" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">具体攻击条件包括：</span></p><ul list="u8aa173dd"><li fid="ue7d98b56" data-lake-id="u6fef7a0b" id="u6fef7a0b"><strong><span data-lake-id="u2e82af78" id="u2e82af78" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">WiFi 条件</span></strong><span data-lake-id="u2f29a692" id="u2f29a692" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：若攻击者靠近 CarPlay 单元，并利用 CarPlay 设备的 WiFi 热点功能，在默认、可预测或已知的热点密码条件下，攻击者可获取访问权限并执行远程代码。</span></li><li fid="ue7d98b56" data-lake-id="u27dbe002" id="u27dbe002"><strong><span data-lake-id="ud5f5ddd2" id="ud5f5ddd2" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">蓝牙条件</span></strong><span data-lake-id="ubbaa8b6c" id="ubbaa8b6c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：某些 CarPlay 设备厂商会通过 IAP2 协议利用蓝牙传输 WiFi 凭据，配对过程中需输入 PIN 码。若攻击者 1）靠近 CarPlay 单元，2）能看到并输入 AirPlay 设备上显示的 PIN 码，则可实施 RCE 攻击。在某些情况下，这是一次单点击 RCE，因为可能需要受害者点击确认。</span></li><li fid="ue7d98b56" data-lake-id="ubcc46c4f" id="ubcc46c4f"><strong><span data-lake-id="u6910166b" id="u6910166b" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">USB 条件</span></strong><span data-lake-id="ucb1aaffa" id="ucb1aaffa" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：非无线版本的 CarPlay 设备可通过物理连接（USB）受到攻击。</span></li></ul><p data-lake-id="ue6b87b3a" id="ue6b87b3a"><span data-lake-id="ue1fe1c48" id="ue1fe1c48" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">攻击效果示例如下：通过显示图像或播放音频干扰驾驶员注意力，或者进行更具隐蔽性的操作，例如窃听谈话或追踪车辆位置。</span></p><p data-lake-id="ubf81d213" id="ubf81d213"><span data-lake-id="u6c6df36e" id="u6c6df36e" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">利用过程，youtube上的视频演示链接：</span><a href="https://www.youtube.com/embed/eq8bUwFuSUM?si=dEfz6cfkdUTkfmCX" target="_blank" data-lake-id="u3155d1aa" id="u3155d1aa"><span data-lake-id="u6efe0575" id="u6efe0575">https://www.youtube.com/embed/eq8bUwFuSUM?si=dEfz6cfkdUTkfmCX</span></a></p><h3 data-lake-id="idbBu" id="idbBu"><strong><span data-lake-id="u170cc130" id="u170cc130" style="color: rgb(51, 51, 51)">其他攻击方式</span></strong></h3><p data-lake-id="udc3daf11" id="udc3daf11"><span data-lake-id="u58d68477" id="u58d68477" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">由于远程代码执行（RCE）漏洞的潜在影响巨大，本文档主要聚焦于该类漏洞的细节。</span></p><p data-lake-id="ubf705f71" id="ubf705f71"><span data-lake-id="u5af105e4" id="u5af105e4" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">然而，正如前文所述，除了 RCE 外，这组漏洞还可能带来其他攻击路径和利用方式，包括：访问控制列表（ACL）和用户交互绕过、本地任意文件读取、敏感信息泄露、中间人攻击（MITM）以及拒绝服务攻击（DoS），这些可能会在未来的博客中进一步提供这些攻击路径与利用方式的详细信息和分析。</span></p><card type="block" name="hr" value="data:%7B%22id%22%3A%22p6vKs%22%7D"></card><h3 data-lake-id="BUC1n" id="BUC1n"><strong><span data-lake-id="uac58d5ce" id="uac58d5ce" style="color: rgb(51, 51, 51)">为何研究 AirPlay</span></strong></h3><p data-lake-id="u70fabfe7" id="u70fabfe7"><span data-lake-id="u60780344" id="u60780344" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">本次研究起源于对 0.0.0.0 day 漏洞：</span><a href="https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser" target="_blank" data-lake-id="u017448cc" id="u017448cc"><span data-lake-id="u86b9d4ab" id="u86b9d4ab">https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser</span></a><span data-lake-id="u2fd6a205" id="u2fd6a205" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">)的调查。在扫描可能通过 </span><em><span data-lake-id="udd0dd84a" id="udd0dd84a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">0.0.0.0</span></em><span data-lake-id="u6793643c" id="u6793643c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 被访问的开放端口时，我们注意到内部网络中的大多数设备都开放了 AirPlay 的 7000 端口。出于对该协议的好奇，我们开始研究 AirPlay 服务器所处理的基础命令。</span></p><p data-lake-id="u4e809fda" id="u4e809fda"><span data-lake-id="ub763fa5b" id="ub763fa5b" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">令人惊讶的是，许多协议命令在默认设置下即可完全访问。在初步分析协议时，我们注意到某些处理流程中的命令存在明显的“代码异味（code smell）”，这些可疑流程促使我们深入挖掘，最终开展了这项广泛的研究工作。</span></p><card type="block" name="hr" value="data:%7B%22id%22%3A%22WLAzW%22%7D"></card><h2 data-lake-id="Lk6I7" id="Lk6I7"><strong><span data-lake-id="u38a04fc7" id="u38a04fc7" style="color: rgb(51, 51, 51)">技术概览</span></strong></h2><h3 data-lake-id="L3nvD" id="L3nvD"><strong><span data-lake-id="u9aa98c79" id="u9aa98c79" style="color: rgb(51, 51, 51)">攻击向量的工作原理</span></strong></h3><p data-lake-id="u0f1ec0bd" id="u0f1ec0bd"><span data-lake-id="u7d3fe36f" id="u7d3fe36f" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">AirPlay 通过端口 </span><em><span data-lake-id="u92990f4d" id="u92990f4d" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">7000</span></em><span data-lake-id="u0a337514" id="u0a337514" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 通信，使用的是一种专有的 </span><em><span data-lake-id="u8bcdec1a" id="u8bcdec1a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">API</span></em><span data-lake-id="u8c24ad13" id="u8c24ad13" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 协议，结合了 </span><em><span data-lake-id="u97d3493e" id="u97d3493e" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">HTTP</span></em><span data-lake-id="u7f9a1699" id="u7f9a1699" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 和 </span><em><span data-lake-id="u00810ac6" id="u00810ac6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">RTSP</span></em><span data-lake-id="uc6cd8eb0" id="uc6cd8eb0" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 协议的特点。在该协议中，许多命令（尤其是需要附加参数的）通过 </span><em><span data-lake-id="uf39a7997" id="uf39a7997" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">HTTP</span></em><span data-lake-id="u049668e0" id="u049668e0" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 的数据负载发送，并采用 </span><em><span data-lake-id="u5b46be57" id="u5b46be57" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">plist</span></em><span data-lake-id="ub4353cf9" id="ub4353cf9" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">（属性列表）格式编码。</span></p><p data-lake-id="ubdbca138" id="ubdbca138"><span data-lake-id="u9b2c5873" id="u9b2c5873" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">属性列表（</span><em><span data-lake-id="u79de7cf2" id="u79de7cf2" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">plist</span></em><span data-lake-id="ua2e69362" id="ua2e69362" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">）是一种在 Apple 生态中广泛使用的结构化数据格式，用于序列化和存储数据。plist 使用键值对的分层结构表示数据，支持多种数据类型，如字符串、数字、日期、布尔值、数组和字典，并可序列化为 </span><em><span data-lake-id="u562c361a" id="u562c361a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">XML</span></em><span data-lake-id="u7cacc5d4" id="u7cacc5d4" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 或二进制格式。</span></p><p data-lake-id="uf7d6b276" id="uf7d6b276"><span data-lake-id="u0f92b4d4" id="u0f92b4d4" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">Apple 的 Core Foundation API 在处理 plist 文件方面起着关键作用，这些 API 提供了读写与序列化 plist 的完整功能。</span></p><p data-lake-id="ua0a83e14" id="ua0a83e14"><span data-lake-id="u9352b234" id="u9352b234" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">由于 plist 是向 AirPlay 接收端传递参数的主要方式，理解 plist 的结构对于掌握整个协议至关重要。更重要的是，许多漏洞都直接与 plist 参数解析流程相关。</span></p><p data-lake-id="udd7f82bb" id="udd7f82bb"><span data-lake-id="u6f6f27ef" id="u6f6f27ef" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">举例来说，CVE-2025-24129 就是一个由于 plist 参数处理不当而引发的类型混淆（Type Confusion）漏洞。由于该漏洞已于 1 月公开，因此我们可以分享一些技术细节。至于其他漏洞（包括本次披露的新漏洞），我们将在确保大多数用户已更新至最新版本、不再受影响之后再行公开技术细节。</span></p><card type="block" name="hr" value="data:%7B%22id%22%3A%22gIe0V%22%7D"></card><h3 data-lake-id="A5S4B" id="A5S4B"><span data-lake-id="u2638831c" id="u2638831c" style="color: rgb(51, 51, 51)">利用 CVE-2025-24129 演示的类型混淆漏洞</span></h3><ul list="u69a87eb5"><li fid="u404e86e7" data-lake-id="uc758fa15" id="uc758fa15"><strong><span data-lake-id="u0d59f673" id="u0d59f673" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">URI</span></strong><span data-lake-id="uabc6228c" id="uabc6228c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：</span><span data-lake-id="u7044eb63" id="u7044eb63" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">/getProperty</span></li><li fid="u404e86e7" data-lake-id="u43e2b281" id="u43e2b281"><strong><span data-lake-id="uce736f39" id="uce736f39" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">方法</span></strong><span data-lake-id="ud05b7be5" id="ud05b7be5" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：</span><span data-lake-id="udc0985ef" id="udc0985ef" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">POST</span></li></ul><p data-lake-id="u924e766f" id="u924e766f"><span data-lake-id="u873af27d" id="u873af27d" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">AirPlay 中的 </span><em><span data-lake-id="u0d77cda5" id="u0d77cda5" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">getProperty</span></em><span data-lake-id="u53e52a9c" id="u53e52a9c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 命令用于从接收端获取特定属性或设置，例如当前的音量级别或设备名称。</span></p><p data-lake-id="u7260f55a" id="u7260f55a"><span data-lake-id="u5acfd902" id="u5acfd902" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">方法 </span><span data-lake-id="ud081788e" id="ud081788e" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">CFPropertyCreateWithData</span><span data-lake-id="u21f60bd9" id="u21f60bd9" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 会将客户端通过 HTTP 发送的数据构造成一个 </span><em><span data-lake-id="u4c88ecea" id="u4c88ecea" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">propertylist</span></em><span data-lake-id="u29b21647" id="u29b21647" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">。该方法根据用户提供的数据内容不同，可能返回不同的 CFType 类型（如 CFArray、CFString 等）。</span></p><p data-lake-id="uc0ce817c" id="uc0ce817c"><card type="inline" name="image" value="data:%7B%22src%22%3A%22https%3A%2F%2Fcdn.prod.website-files.com%2F63e8dd453f71270c6845992b%2F6810a4cb8d96a04b420a5286_AD_4nXf-fTc3qyMYETRMKjhkuRNTbZ7y40xWp_nzwnf67LDJVTjvxC7mdp2QOrerl7GsWaJjyXOI1ZMhnv-AJeFJyehN8ldmNdPGd99ITSJiBZlCP22lKItRcMCoUbhIdcEdb44sOEZRIg.png%22%2C%22originalType%22%3A%22binary%22%2C%22linkTarget%22%3A%22_blank%22%2C%22from%22%3A%22url%22%2C%22originWidth%22%3A1294%2C%22originHeight%22%3A293%2C%22ratio%22%3A1%2C%22status%22%3A%22done%22%2C%22style%22%3A%22none%22%2C%22showTitle%22%3Afalse%2C%22title%22%3A%22%22%2C%22rotation%22%3A0%2C%22crop%22%3A%5B0%2C0%2C1%2C1%5D%2C%22id%22%3A%22vZabs%22%2C%22margin%22%3A%7B%22top%22%3Atrue%2C%22bottom%22%3Atrue%7D%7D" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"></card></p><p data-lake-id="uc91fbce9" id="uc91fbce9"><span data-lake-id="u0e84d779" id="u0e84d779" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">如上图所示，使用 </span><span data-lake-id="u3b3f02bc" id="u3b3f02bc" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">CFPropertyListCreateWithData</span><span data-lake-id="u91015e35" id="u91015e35" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 创建了一个属性列表（</span><em><span data-lake-id="ud53bc52f" id="ud53bc52f" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">property list</span></em><span data-lake-id="uff103b06" id="uff103b06" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">），但返回结果的类型（</span><em><span data-lake-id="u06ee44bf" id="u06ee44bf" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CFType</span></em><span data-lake-id="ue564aae5" id="ue564aae5" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">）并未进行校验，程序默认其为字典类型（</span><em><span data-lake-id="u981200df" id="u981200df" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CFDictionary</span></em><span data-lake-id="u0685f09b" id="u0685f09b" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">）。</span><span data-lake-id="u53283c53" id="u53283c53" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 如果实际创建的 plist 不是一个 </span><em><span data-lake-id="u6453d0ba" id="u6453d0ba" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CFDictionary</span></em><span data-lake-id="u8eab2c6a" id="u8eab2c6a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">，那么在调用如 </span><span data-lake-id="uda55c456" id="uda55c456" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">CFDictionaryGetValue</span><span data-lake-id="u27387d4e" id="u27387d4e" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 这类函数时，程序将会崩溃。</span></p><p data-lake-id="u8164a700" id="u8164a700"><strong><span data-lake-id="u6e709316" id="u6e709316" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">可利用性分析</span></strong><span data-lake-id="uff9ec334" id="uff9ec334" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：</span><span data-lake-id="u2e5a906a" id="u2e5a906a" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">CFDictionaryGetValue</span><span data-lake-id="udf6801a3" id="udf6801a3" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 属于 CoreFoundation 库的一部分，因此该问题的可利用性取决于具体的 CoreFoundation 版本。我们发现，大多数类型混淆漏洞在不同版本的 CoreFoundation 中，其可利用性也存在差异。</span></p><card type="block" name="hr" value="data:%7B%22id%22%3A%22S1myc%22%7D"></card><h3 data-lake-id="JJ8qP" id="JJ8qP"><strong><span data-lake-id="ue9cec31f" id="ue9cec31f" style="color: rgb(51, 51, 51)">未获得 CVE 编号的漏洞</span></strong></h3><p data-lake-id="uca800f09" id="uca800f09"><span data-lake-id="u6765a13c" id="u6765a13c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">Oligo Security 研究团队向 Apple 报告了共计 23 个漏洞。这些漏洞均已被修复，但并非所有漏洞都获得了 CVE 编号。</span><span data-lake-id="u022beca9" id="u022beca9" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 在某些情况下，Apple 会根据修复方式和修复时间将多个漏洞归类为同一个 CVE，而非按漏洞类型、影响范围或在 AirPlay 协议代码中的位置进行区分。</span></p><p data-lake-id="u8e1ed6e6" id="u8e1ed6e6"><span data-lake-id="u9a153478" id="u9a153478" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">以下是两个未获得 CVE 编号的漏洞示例：</span></p><card type="block" name="hr" value="data:%7B%22id%22%3A%22fLrBe%22%7D"></card><h4 data-lake-id="w9jUS" id="w9jUS"><strong><span data-lake-id="ud48529e6" id="ud48529e6" style="color: rgb(51, 51, 51)">/setProperty 路由崩溃漏洞</span></strong></h4><ul list="u98b679e2"><li fid="ufd1512af" data-lake-id="ud91be7f3" id="ud91be7f3"><strong><span data-lake-id="u46890856" id="u46890856" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">URI</span></strong><span data-lake-id="u65a97d07" id="u65a97d07" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：</span><span data-lake-id="ud970263a" id="ud970263a" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">/setProperty</span></li><li fid="ufd1512af" data-lake-id="u88934d72" id="u88934d72"><strong><span data-lake-id="u947e19fc" id="u947e19fc" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">方法</span></strong><span data-lake-id="ub5adf745" id="ub5adf745" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：</span><span data-lake-id="ub9d49d17" id="ub9d49d17" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">PUT</span></li><li fid="ufd1512af" data-lake-id="u2d1e28f7" id="u2d1e28f7"><strong><span data-lake-id="u768eece7" id="u768eece7" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">适用配置</span></strong><span data-lake-id="u1c406931" id="u1c406931" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：全部设备</span></li><li fid="ufd1512af" data-lake-id="ud02991ba" id="ud02991ba"><strong><span data-lake-id="ub4300093" id="ub4300093" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">用户交互</span></strong><span data-lake-id="u675b4008" id="u675b4008" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：需要用户点击一次以接受连接</span></li></ul><p data-lake-id="u51ac6e3b" id="u51ac6e3b"><span data-lake-id="u2e828908" id="u2e828908" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">AirPlay 中的 </span><em><span data-lake-id="ue50f3023" id="ue50f3023" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">setProperty</span></em><span data-lake-id="u11658afd" id="u11658afd" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 命令允许发送端配置接收端的某些属性或设置，如调节音量、播放选项或设备特定功能。</span></p><p data-lake-id="ubd9d07d3" id="ubd9d07d3"><span data-lake-id="u6504136b" id="u6504136b" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">大多数 AirPlay 的 </span><em><span data-lake-id="u50f36d55" id="u50f36d55" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">POST</span></em><span data-lake-id="ueaa2f22a" id="ueaa2f22a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">/</span><em><span data-lake-id="ue9172cce" id="ue9172cce" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">PUT</span></em><span data-lake-id="u4c440c5d" id="u4c440c5d" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 命令都要求 HTTP 请求中的数据以 plist 格式提供。</span></p><p data-lake-id="u6b6f4378" id="u6b6f4378"><card type="inline" name="image" value="data:%7B%22src%22%3A%22https%3A%2F%2Fcdn.prod.website-files.com%2F63e8dd453f71270c6845992b%2F6810a511a314ebfe5295af9f_AD_4nXeNYAS3cfb0VXIHHSI3QPm4Wm5-_BMHZY09b99Y88Mr9k4bYk5K65x5-7BqGXE4fR7hOSh56zUjUTupc1nCVlqzb1jiTO_VR4E4Tcckf5q-ql3HSsDLQu-QvQIRifbnS-Upkp-VuQ.png%22%2C%22originalType%22%3A%22binary%22%2C%22linkTarget%22%3A%22_blank%22%2C%22from%22%3A%22url%22%2C%22originWidth%22%3A752%2C%22originHeight%22%3A161%2C%22ratio%22%3A1%2C%22status%22%3A%22done%22%2C%22style%22%3A%22none%22%2C%22showTitle%22%3Afalse%2C%22title%22%3A%22%22%2C%22rotation%22%3A0%2C%22crop%22%3A%5B0%2C0%2C1%2C1%5D%2C%22id%22%3A%22vXQXp%22%2C%22margin%22%3A%7B%22top%22%3Atrue%2C%22bottom%22%3Atrue%7D%7D" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"></card></p><p data-lake-id="uece60dde" id="uece60dde"><span data-lake-id="u33f403c7" id="u33f403c7" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">在 </span><span data-lake-id="u060b013f" id="u060b013f" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">mcProcessor_requestProcessSetProxiedProperty</span><span data-lake-id="u0efa2673" id="u0efa2673" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 中对 </span><em><span data-lake-id="u124944b6" id="u124944b6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">HTTP</span></em><span data-lake-id="uddf6a891" id="uddf6a891" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 数据 plist 的格式化处理：</span></p><p data-lake-id="ub44760ba" id="ub44760ba"><span data-lake-id="ub7c5f7c6" id="ub7c5f7c6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">服务器期望在 </span><em><span data-lake-id="u3912f93b" id="u3912f93b" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">/setProperty</span></em><span data-lake-id="u5f5532ed" id="u5f5532ed" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 的 </span><em><span data-lake-id="ub596941e" id="ub596941e" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">plist</span></em><span data-lake-id="u47d3f786" id="u47d3f786" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 载荷中包含一个 </span><span data-lake-id="u870b5d62" id="u870b5d62" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">value</span><span data-lake-id="u22d744d6" id="u22d744d6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 键。</span></p><p data-lake-id="u135751c7" id="u135751c7"><span data-lake-id="u5b38f812" id="u5b38f812" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">value</span><span data-lake-id="u40bd2f45" id="u40bd2f45" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 变量在未检查是否为 null 的情况下被用于构造响应：</span></p><p data-lake-id="u82f8d918" id="u82f8d918"><card type="inline" name="image" value="data:%7B%22src%22%3A%22https%3A%2F%2Fcdn.prod.website-files.com%2F63e8dd453f71270c6845992b%2F6810a51182aa2f89fb6dfe01_AD_4nXfWDse7gC0HxEqyEq4GnzfrXkwvqnC_SuEiDlRBm1FzX0XfDH3dNV5tJLFVne9v_hDVh529sHHc-qvhvPQlb0mzFEe-oo2ip7HUz064qOx-el-pbkiWGlVa3C1aAf76VJiW2JHsNQ.png%22%2C%22originalType%22%3A%22binary%22%2C%22linkTarget%22%3A%22_blank%22%2C%22from%22%3A%22url%22%2C%22originWidth%22%3A798%2C%22originHeight%22%3A202%2C%22ratio%22%3A1%2C%22status%22%3A%22done%22%2C%22style%22%3A%22none%22%2C%22showTitle%22%3Afalse%2C%22title%22%3A%22%22%2C%22rotation%22%3A0%2C%22crop%22%3A%5B0%2C0%2C1%2C1%5D%2C%22id%22%3A%22Fti7q%22%2C%22margin%22%3A%7B%22top%22%3Atrue%2C%22bottom%22%3Atrue%7D%7D" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"></card></p><p data-lake-id="u06d2cb6c" id="u06d2cb6c"><span data-lake-id="u47005949" id="u47005949" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">如果用户在请求中未发送 </span><span data-lake-id="uad1db214" id="uad1db214" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">value</span><span data-lake-id="u89eb449f" id="u89eb449f" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 键，它将保持为 null。</span><span data-lake-id="u182939fc" id="u182939fc" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 在此情况下调用 </span><em><span data-lake-id="u07e5ca9e" id="u07e5ca9e" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CFDictionarySetValue</span></em><span data-lake-id="ue95eee15" id="ue95eee15" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 会因传入 null 而触发未处理异常，导致 </span><em><span data-lake-id="u9818a2ba" id="u9818a2ba" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">ControlCenter</span></em><span data-lake-id="ud4c1b313" id="ud4c1b313" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 进程崩溃。</span></p><card type="block" name="hr" value="data:%7B%22id%22%3A%22GrBOb%22%7D"></card><h4 data-lake-id="tfFNP" id="tfFNP"><strong><span data-lake-id="u2d4c7081" id="u2d4c7081" style="color: rgb(51, 51, 51)">通过 WindowServer 崩溃实现远程用户注销</span></strong></h4><ul list="u5707080d"><li fid="u559437fd" data-lake-id="u972675a7" id="u972675a7"><strong><span data-lake-id="u731dfaa1" id="u731dfaa1" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">URI</span></strong><span data-lake-id="u57dc7b40" id="u57dc7b40" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：</span><span data-lake-id="u35432c52" id="u35432c52" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">rtsp://&lt;ip&gt;/stream</span></li><li fid="u559437fd" data-lake-id="u14a92056" id="u14a92056"><strong><span data-lake-id="ud10a4ac8" id="ud10a4ac8" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">方法</span></strong><span data-lake-id="u0cb7fb56" id="u0cb7fb56" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：SETUP</span></li><li fid="u559437fd" data-lake-id="ucfd9257c" id="ucfd9257c"><strong><span data-lake-id="ua66d3983" id="ua66d3983" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">适用配置</span></strong><span data-lake-id="u807cbf46" id="u807cbf46" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：同一网络中的任意用户 / 所有人</span></li><li fid="u559437fd" data-lake-id="uefdd6ab6" id="uefdd6ab6"><strong><span data-lake-id="u0758d9a5" id="u0758d9a5" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">用户交互</span></strong><span data-lake-id="u97b648c5" id="u97b648c5" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：使用 CVE-2025-24206 实现 0 点击攻击</span></li></ul><p data-lake-id="u8f2925fd" id="u8f2925fd"><span data-lake-id="uce1eadb6" id="uce1eadb6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">AirPlay 中的 SETUP 方法基于 RTSP（实时流传输协议），用于从发送端（如 iPhone/iPad）向接收端（如 Apple TV）发起媒体流。</span></p><p data-lake-id="ubcb40e28" id="ubcb40e28"><span data-lake-id="u46f1bcb5" id="u46f1bcb5" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">发送多个 SETUP 命令会创建多个视频流。由于系统未限制流数量，我们可以通过 </span><span data-lake-id="u6e3b8c00" id="u6e3b8c00" class="lake-fontsize-12" style="color: rgb(51, 51, 51); background-color: rgb(243, 244, 244)">while</span><span data-lake-id="u40f01970" id="u40f01970" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 循环持续创建流。</span><span data-lake-id="uf78ed56d" id="uf78ed56d" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"> 持续发送大量流会增加 WindowServer 服务的内存占用和响应时间。几秒钟后，</span><strong><span data-lake-id="uf0d9b421" id="uf0d9b421" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">看门狗（watchdog）会终止 WindowServer 服务，导致用户被强制注销。</span></strong></p><p data-lake-id="uc96f4fc4" id="uc96f4fc4"><span data-lake-id="uc280d8fa" id="uc280d8fa" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">该漏洞允许网络内或附近的攻击者远程强制注销用户。</span></p><p data-lake-id="u14cf6486" id="u14cf6486"><span data-lake-id="u134881db" id="u134881db" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">利用过程，youtube上的视频演示链接：</span><a href="https://www.youtube.com/embed/RODsw_eXB5g?si=6-0QL0-HZmynZmsS" target="_blank" data-lake-id="u0223a0e5" id="u0223a0e5"><span data-lake-id="uc9d8e7f7" id="uc9d8e7f7">https://www.youtube.com/embed/RODsw_eXB5g?si=6-0QL0-HZmynZmsS</span></a></p><h2 data-lake-id="JW4xa" id="JW4xa"><strong><span data-lake-id="ud26faf9e" id="ud26faf9e" style="color: rgb(51, 51, 51)">AirBorne 漏洞</span></strong></h2><p data-lake-id="udafb8205" id="udafb8205"><span data-lake-id="u846b78c1" id="u846b78c1" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">AirBorne 漏洞使设备暴露于多种攻击之下，每类漏洞都带来了独特的安全风险。以下是对各类漏洞功能与潜在影响的分析。</span></p><h3 data-lake-id="PHq4Z" id="PHq4Z"><strong><span data-lake-id="u25226e7c" id="u25226e7c" style="color: rgb(51, 51, 51)">ACL 和用户交互绕过</span></strong></h3><p data-lake-id="u9ad0441b" id="u9ad0441b"><span data-lake-id="u90c38b5a" id="u90c38b5a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">AirPlay 使用两项主要功能来处理访问权限控制：</span></p><ul list="u48522c83"><li fid="uad0cbdce" data-lake-id="u7fba4f04" id="u7fba4f04"><strong><span data-lake-id="u96fb8156" id="u96fb8156" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">ACL（访问控制列表）</span></strong><span data-lake-id="u8840df0d" id="u8840df0d" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：根据 AirPlay 接收端的配置限制访问权限。</span></li></ul><p data-lake-id="uce340ce9" id="uce340ce9"><card type="inline" name="image" value="data:%7B%22src%22%3A%22https%3A%2F%2Fcdn.prod.website-files.com%2F63e8dd453f71270c6845992b%2F6810a7a33f366c2fdc76b956_AD_4nXcoa2VKLAjjAFHSLPU6HBIrkbX04zVdQtUQ4vV47bZ-Mc6hlWNFR_wqZ-I0rFxVm1eop18KD5v7cTMYlKGdqQvC86IAVsWn1ZFf0ZSaWLE-Zl94dBqNuqG-WK37TkhxFKza0oFt9Q.png%22%2C%22originalType%22%3A%22binary%22%2C%22linkTarget%22%3A%22_blank%22%2C%22from%22%3A%22url%22%2C%22originWidth%22%3A299%2C%22originHeight%22%3A69%2C%22ratio%22%3A1%2C%22status%22%3A%22done%22%2C%22style%22%3A%22none%22%2C%22showTitle%22%3Afalse%2C%22title%22%3A%22%22%2C%22rotation%22%3A0%2C%22crop%22%3A%5B0%2C0%2C1%2C1%5D%2C%22id%22%3A%22TgctC%22%2C%22margin%22%3A%7B%22top%22%3Atrue%2C%22bottom%22%3Atrue%7D%7D" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"></card></p><ul list="u06033a2a"><li fid="ua51cd67e" data-lake-id="u7a373fde" id="u7a373fde"><span data-lake-id="uc638b425" id="uc638b425" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">点击接受 – 某些操作要求用户点击“接受”并批准 AirPlay 连接。</span></li></ul><p data-lake-id="u679cc142" id="u679cc142"><card type="inline" name="image" value="data:%7B%22src%22%3A%22https%3A%2F%2Fcdn.prod.website-files.com%2F63e8dd453f71270c6845992b%2F6810a7a230c3225f68261298_AD_4nXdnj1753RkXARzjy8DITN0vlLUP_FA77SUPKNhbjMpMZgV0CZgjEnXxWDt4ZD5ZSkrq4mAf-WG_vUmiK5FhcrUXtvE_AArpHG8cwKBt85-B_RClRzzGzHXH1aPf0Tu2i5cMOE79CQ.png%22%2C%22originalType%22%3A%22binary%22%2C%22linkTarget%22%3A%22_blank%22%2C%22from%22%3A%22url%22%2C%22originWidth%22%3A370%2C%22originHeight%22%3A94%2C%22ratio%22%3A1%2C%22status%22%3A%22done%22%2C%22style%22%3A%22none%22%2C%22showTitle%22%3Afalse%2C%22title%22%3A%22%22%2C%22rotation%22%3A0%2C%22crop%22%3A%5B0%2C0%2C1%2C1%5D%2C%22id%22%3A%22ztCUU%22%2C%22margin%22%3A%7B%22top%22%3Atrue%2C%22bottom%22%3Atrue%7D%7D" class="lake-fontsize-12" style="color: rgb(51, 51, 51)"></card></p><p data-lake-id="ubc571012" id="ubc571012"><span data-lake-id="u5a7cb70c" id="u5a7cb70c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">我们发现了多个 ACL 绕过漏洞和问题，以及一个用户交互绕过问题，这使得在 macOS 设备配置为 AirPlay 接收器默认设置并设置为“当前用户”时，AirBorne 漏洞可以实现许多攻击。</span></p><p data-lake-id="ufa5d96f3" id="ufa5d96f3"><span data-lake-id="u29006234" id="u29006234" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24206 还</span><strong><span data-lake-id="u3f17d19d" id="u3f17d19d" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">通过绕过“Accept”点击要求</span></strong><span data-lake-id="u3e9edf61" id="u3e9edf61" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">使许多攻击成为零点击攻击。</span></p><p data-lake-id="u876afd05" id="u876afd05"><strong><span data-lake-id="u3a28e02d" id="u3a28e02d" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">用户交互绕过</span></strong></p><table data-lake-id="H88VR" id="H88VR" class="lake-table" style="width: 750px"><colgroup><col width="250"><col width="250"><col width="250"></colgroup><tbody><tr data-lake-id="uf2a2e0d0" id="uf2a2e0d0"><td data-lake-id="ub7f6680f" id="ub7f6680f"><p data-lake-id="ubc210d8b" id="ubc210d8b" style="text-align: left"><strong><span data-lake-id="ud7db1549" id="ud7db1549" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE</span></strong></p></td><td data-lake-id="u75df431d" id="u75df431d"><p data-lake-id="uffcbf2e1" id="uffcbf2e1" style="text-align: left"><strong><span data-lake-id="u6b464b11" id="u6b464b11" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE</span></strong></p></td><td data-lake-id="u81845bd0" id="u81845bd0"><p data-lake-id="u0e34aaaf" id="u0e34aaaf" style="text-align: left"><strong><span data-lake-id="u22e915bb" id="u22e915bb" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">影响范围&amp;公告</span></strong></p></td></tr><tr data-lake-id="uf45287de" id="uf45287de"><td data-lake-id="uf7205f3a" id="uf7205f3a"><p data-lake-id="ubc2ffb0b" id="ubc2ffb0b" style="text-align: left"><span data-lake-id="ua70d6e57" id="ua70d6e57" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24206</span></p></td><td data-lake-id="u961d2eb2" id="u961d2eb2"><p data-lake-id="ub626c9ca" id="ub626c9ca" style="text-align: left"><span data-lake-id="u941b8d09" id="u941b8d09" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-288: Authentication Bypass Using an Alternate Path or Channel</span></p></td><td data-lake-id="uc03221c4" id="uc03221c4"><p data-lake-id="u8baf1b27" id="u8baf1b27" style="text-align: left"><a href="https://support.apple.com/en-us/122377" target="_blank" data-lake-id="uf5c04ce6" id="uf5c04ce6"><span data-lake-id="u01ecda25" id="u01ecda25">tvOS 18.4</span></a></p><p data-lake-id="u14619771" id="u14619771" style="text-align: left"><a href="https://support.apple.com/en-us/122371" target="_blank" data-lake-id="u8af2f8ba" id="u8af2f8ba"><span data-lake-id="u73a80cbe" id="u73a80cbe">iOS 18.4 and iPadOS 18.4</span></a></p><p data-lake-id="ucc7ced06" id="ucc7ced06" style="text-align: left"><a href="https://support.apple.com/en-us/122372" target="_blank" data-lake-id="u80badcd2" id="u80badcd2"><span data-lake-id="u1c02ed7d" id="u1c02ed7d">iPadOS 17.7.6</span></a></p><p data-lake-id="ua99c3087" id="ua99c3087" style="text-align: left"><a href="https://support.apple.com/en-us/122373" target="_blank" data-lake-id="u0cb1e73a" id="u0cb1e73a"><span data-lake-id="uc2b26e49" id="uc2b26e49">macOS Sequoia 15.4</span></a></p><p data-lake-id="u4b7fe1d8" id="u4b7fe1d8" style="text-align: left"><a href="https://support.apple.com/en-us/122378" target="_blank" data-lake-id="ufb266350" id="ufb266350"><span data-lake-id="uce919b3e" id="uce919b3e">visionOS 2.4</span></a></p><p data-lake-id="uc22cb9ed" id="uc22cb9ed" style="text-align: left"><a href="https://support.apple.com/en-us/122374" target="_blank" data-lake-id="u913fe10e" id="u913fe10e"><span data-lake-id="u0850a6d2" id="u0850a6d2">macOS Sonoma 14.7.5</span></a></p><p data-lake-id="u3be80762" id="u3be80762" style="text-align: left"><a href="https://support.apple.com/en-us/122375" target="_blank" data-lake-id="u6f74e3bd" id="u6f74e3bd"><span data-lake-id="ub30a882f" id="ub30a882f">macOS Ventura 13.7.5</span></a></p></td></tr></tbody></table><p data-lake-id="u9aa9bf96" id="u9aa9bf96"><strong><span data-lake-id="u0e1e91c6" id="u0e1e91c6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">ACL 问题和绕过</span></strong></p><table data-lake-id="MRFWF" id="MRFWF" class="lake-table" style="width: 750px"><colgroup><col width="250"><col width="250"><col width="250"></colgroup><tbody><tr data-lake-id="u35cc3b58" id="u35cc3b58"><td data-lake-id="u0fac11bd" id="u0fac11bd"><p data-lake-id="uab50d4f6" id="uab50d4f6" style="text-align: left"><strong><span data-lake-id="uf8c75b7b" id="uf8c75b7b" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE</span></strong></p></td><td data-lake-id="u7244bff5" id="u7244bff5"><p data-lake-id="ua656925d" id="ua656925d" style="text-align: left"><strong><span data-lake-id="u1a9560d0" id="u1a9560d0" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE</span></strong></p></td><td data-lake-id="u028c65a2" id="u028c65a2"><p data-lake-id="u1f2e9bf9" id="u1f2e9bf9" style="text-align: left"><strong><span data-lake-id="ub8f11401" id="ub8f11401" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">影响范围&amp;公告</span></strong></p></td></tr><tr data-lake-id="u76b26dbc" id="u76b26dbc"><td data-lake-id="ud72faa20" id="ud72faa20"><p data-lake-id="udc16ca27" id="udc16ca27" style="text-align: left"><span data-lake-id="u9787cdf0" id="u9787cdf0" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24271 (Group) – Improper Access Control</span></p></td><td data-lake-id="u9a0d9401" id="u9a0d9401"><p data-lake-id="ue88b3566" id="ue88b3566" style="text-align: left"><span data-lake-id="u6acbbbf4" id="u6acbbbf4" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-306: Missing Authentication for Critical Function</span></p></td><td data-lake-id="u237dc085" id="u237dc085"><p data-lake-id="u3d7558a2" id="u3d7558a2" style="text-align: left"><a href="https://support.apple.com/en-us/122377" target="_blank" data-lake-id="u6a1c626f" id="u6a1c626f"><span data-lake-id="u81fdf934" id="u81fdf934">tvOS 18.4</span></a></p><p data-lake-id="u888ef4b9" id="u888ef4b9" style="text-align: left"><a href="https://support.apple.com/en-us/122371" target="_blank" data-lake-id="ub9152f95" id="ub9152f95"><span data-lake-id="uae71fc4f" id="uae71fc4f">iOS 18.4 and iPadOS 18.4</span></a></p><p data-lake-id="u583fe198" id="u583fe198" style="text-align: left"><a href="https://support.apple.com/en-us/122372" target="_blank" data-lake-id="uba3930ab" id="uba3930ab"><span data-lake-id="udeacb1f5" id="udeacb1f5">iPadOS 17.7.6</span></a></p><p data-lake-id="u501f3f3e" id="u501f3f3e" style="text-align: left"><a href="https://support.apple.com/en-us/122373" target="_blank" data-lake-id="u236724db" id="u236724db"><span data-lake-id="u56d1a20d" id="u56d1a20d">macOS Sequoia 15.4</span></a></p><p data-lake-id="u8faf053c" id="u8faf053c" style="text-align: left"><a href="https://support.apple.com/en-us/122378" target="_blank" data-lake-id="u57e2ead7" id="u57e2ead7"><span data-lake-id="u40f0b467" id="u40f0b467">visionOS 2.4</span></a></p><p data-lake-id="u16265ce4" id="u16265ce4" style="text-align: left"><a href="https://support.apple.com/en-us/122374" target="_blank" data-lake-id="u8760c1c6" id="u8760c1c6"><span data-lake-id="u50cfac5c" id="u50cfac5c">macOS Sonoma 14.7.5</span></a></p><p data-lake-id="u17a8ef3e" id="u17a8ef3e" style="text-align: left"><a href="https://support.apple.com/en-us/122375" target="_blank" data-lake-id="u161840f5" id="u161840f5"><span data-lake-id="u3210221c" id="u3210221c">macOS Ventura 13.7.5</span></a></p></td></tr><tr data-lake-id="u0a567fb3" id="u0a567fb3"><td data-lake-id="ub1e57466" id="ub1e57466" style="background-color: rgb(248, 248, 248)"><p data-lake-id="ud75b15e3" id="ud75b15e3" style="text-align: left"><span data-lake-id="u75f29086" id="u75f29086" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24271 (Group) – type confusion</span></p></td><td data-lake-id="u548fa749" id="u548fa749" style="background-color: rgb(248, 248, 248)"><p data-lake-id="ud5eeebfb" id="ud5eeebfb" style="text-align: left"><span data-lake-id="ubf5822f6" id="ubf5822f6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-843: Access of Resource Using Incompatible Type (‘Type Confusion’)</span></p></td><td data-lake-id="u48a14759" id="u48a14759" style="background-color: rgb(248, 248, 248)"><p data-lake-id="uafa25cf6" id="uafa25cf6" style="text-align: left"><a href="https://support.apple.com/en-us/122377" target="_blank" data-lake-id="u7b010e8e" id="u7b010e8e"><span data-lake-id="u3b3d590f" id="u3b3d590f">tvOS 18.4</span></a></p><p data-lake-id="uabbc50b3" id="uabbc50b3" style="text-align: left"><a href="https://support.apple.com/en-us/122371" target="_blank" data-lake-id="u8e65869f" id="u8e65869f"><span data-lake-id="u7dc28638" id="u7dc28638">iOS 18.4 and iPadOS 18.4</span></a></p><p data-lake-id="u50eeb4b6" id="u50eeb4b6" style="text-align: left"><a href="https://support.apple.com/en-us/122372" target="_blank" data-lake-id="u649a5ebd" id="u649a5ebd"><span data-lake-id="ud39892b8" id="ud39892b8">iPadOS 17.7.6</span></a></p><p data-lake-id="uaec085a6" id="uaec085a6" style="text-align: left"><a href="https://support.apple.com/en-us/122373" target="_blank" data-lake-id="u0c36c728" id="u0c36c728"><span data-lake-id="u61205f45" id="u61205f45">macOS Sequoia 15.4</span></a></p><p data-lake-id="u69a8442a" id="u69a8442a" style="text-align: left"><a href="https://support.apple.com/en-us/122378" target="_blank" data-lake-id="u4cf391e2" id="u4cf391e2"><span data-lake-id="ub7bcc2b9" id="ub7bcc2b9">visionOS 2.4</span></a></p><p data-lake-id="u5ae48f50" id="u5ae48f50" style="text-align: left"><a href="https://support.apple.com/en-us/122374" target="_blank" data-lake-id="udd3e6878" id="udd3e6878"><span data-lake-id="uf5ff9a68" id="uf5ff9a68">macOS Sonoma 14.7.5</span></a></p><p data-lake-id="u96f22ccc" id="u96f22ccc" style="text-align: left"><a href="https://support.apple.com/en-us/122375" target="_blank" data-lake-id="u6ad5b3ad" id="u6ad5b3ad"><span data-lake-id="ue2ebf669" id="ue2ebf669">macOS Ventura 13.7.5</span></a></p></td></tr></tbody></table><p data-lake-id="uec244fd3" id="uec244fd3"><strong><span data-lake-id="u0cbff841" id="u0cbff841" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">远程代码执行 (RCE)</span></strong></p><p data-lake-id="uf315aa77" id="uf315aa77"><span data-lake-id="ucc162aa9" id="ucc162aa9" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">该套件中最严重的漏洞允许远程代码执行，使攻击者能够完全接管易受攻击的设备。这些漏洞使得 AirBorne 可以被蠕虫化。在攻陷一个设备后，攻击者可以利用相同的漏洞传播到其他设备和网络，进一步扩大影响和破坏。</span></p><p data-lake-id="ue770e1c9" id="ue770e1c9"><span data-lake-id="ue9b9afa9" id="ue9b9afa9" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">以下是可以用于接管设备（RCE）的漏洞。</span></p><table data-lake-id="k3d86" id="k3d86" class="lake-table" style="width: 750px"><colgroup><col width="250"><col width="250"><col width="250"></colgroup><tbody><tr data-lake-id="u3fc2c59d" id="u3fc2c59d"><td data-lake-id="u903a023a" id="u903a023a"><p data-lake-id="u958ceeb4" id="u958ceeb4" style="text-align: left"><strong><span data-lake-id="u0bfc0664" id="u0bfc0664" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE</span></strong></p></td><td data-lake-id="ub46c8edc" id="ub46c8edc"><p data-lake-id="ueaa2eb4f" id="ueaa2eb4f" style="text-align: left"><strong><span data-lake-id="u1d5968df" id="u1d5968df" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE</span></strong></p></td><td data-lake-id="ua37c55e1" id="ua37c55e1"><p data-lake-id="u60654abc" id="u60654abc" style="text-align: left"><strong><span data-lake-id="u8d70ed7d" id="u8d70ed7d" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">影响范围&amp;公告</span></strong></p></td></tr><tr data-lake-id="u4b976dbe" id="u4b976dbe"><td data-lake-id="uf3beb0b3" id="uf3beb0b3"><p data-lake-id="u66ed9213" id="u66ed9213" style="text-align: left"><span data-lake-id="ufd518a82" id="ufd518a82" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24132</span></p></td><td data-lake-id="u6e789217" id="u6e789217"><p data-lake-id="u293a0cc5" id="u293a0cc5" style="text-align: left"><span data-lake-id="ue477030a" id="ue477030a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-121: Stack-based Buffer Overflow</span></p></td><td data-lake-id="u0dcfe1a5" id="u0dcfe1a5"><p data-lake-id="uba61aeba" id="uba61aeba" style="text-align: left"><a href="https://support.apple.com/en-us/122403" target="_blank" data-lake-id="u1b317fb3" id="u1b317fb3"><span data-lake-id="uf4aca930" id="uf4aca930">AirPlay audio SDK 2.7.1 AirPlay video SDK 3.6.0.126 CarPlay Communication Plug-in R18.1</span></a></p></td></tr><tr data-lake-id="u78d64455" id="u78d64455"><td data-lake-id="u144be46a" id="u144be46a" style="background-color: rgb(248, 248, 248)"><p data-lake-id="u2b01b183" id="u2b01b183" style="text-align: left"><span data-lake-id="u9d1b3381" id="u9d1b3381" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-30422 (potential RCE)</span></p></td><td data-lake-id="u420ff6e5" id="u420ff6e5" style="background-color: rgb(248, 248, 248)"><p data-lake-id="uffa6b068" id="uffa6b068" style="text-align: left"><span data-lake-id="ufa8842de" id="ufa8842de" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-190: Integer Overflow or Wraparound</span></p></td><td data-lake-id="u3c31866e" id="u3c31866e" style="background-color: rgb(248, 248, 248)"><p data-lake-id="ua2c6f1a7" id="ua2c6f1a7" style="text-align: left"><a href="https://support.apple.com/en-us/122403" target="_blank" data-lake-id="u0897781d" id="u0897781d"><span data-lake-id="u8717644f" id="u8717644f">AirPlay audio SDK 2.7.1 AirPlay video SDK 3.6.0.126 CarPlay Communication Plug-in R18.1</span></a></p></td></tr><tr data-lake-id="u66394ca6" id="u66394ca6"><td data-lake-id="uc137db92" id="uc137db92"><p data-lake-id="ube7f194a" id="ube7f194a" style="text-align: left"><span data-lake-id="u07a4d4ac" id="u07a4d4ac" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24252</span></p></td><td data-lake-id="u9420c350" id="u9420c350"><p data-lake-id="u3d2792b9" id="u3d2792b9" style="text-align: left"><span data-lake-id="ufaab10dc" id="ufaab10dc" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-416: Use After Free</span></p></td><td data-lake-id="u0f7f3632" id="u0f7f3632"><p data-lake-id="u5f594fd8" id="u5f594fd8" style="text-align: left"><a href="https://support.apple.com/en-us/122377" target="_blank" data-lake-id="ubc680a49" id="ubc680a49"><span data-lake-id="u535d90fe" id="u535d90fe">tvOS 18.4</span></a></p><p data-lake-id="u8ce20bf7" id="u8ce20bf7" style="text-align: left"><a href="https://support.apple.com/en-us/122371" target="_blank" data-lake-id="ua532bf87" id="ua532bf87"><span data-lake-id="ue1ec0425" id="ue1ec0425">iOS 18.4 and iPadOS 18.4</span></a></p><p data-lake-id="u9f038376" id="u9f038376" style="text-align: left"><a href="https://support.apple.com/en-us/122372" target="_blank" data-lake-id="u66829891" id="u66829891"><span data-lake-id="u11728773" id="u11728773">iPadOS 17.7.6</span></a></p><p data-lake-id="u5ae6be58" id="u5ae6be58" style="text-align: left"><a href="https://support.apple.com/en-us/122373" target="_blank" data-lake-id="u02d97f52" id="u02d97f52"><span data-lake-id="u83cf6e87" id="u83cf6e87">macOS Sequoia 15.4</span></a></p><p data-lake-id="u9c486ba9" id="u9c486ba9" style="text-align: left"><a href="https://support.apple.com/en-us/122378" target="_blank" data-lake-id="u0aba20d9" id="u0aba20d9"><span data-lake-id="u5ac9526b" id="u5ac9526b">visionOS 2.4</span></a></p><p data-lake-id="u6bcdeb70" id="u6bcdeb70" style="text-align: left"><a href="https://support.apple.com/en-us/122374" target="_blank" data-lake-id="udcb155e3" id="udcb155e3"><span data-lake-id="ubc5920c1" id="ubc5920c1">macOS Sonoma 14.7.5</span></a></p><p data-lake-id="u2ce23653" id="u2ce23653" style="text-align: left"><a href="https://support.apple.com/en-us/122375" target="_blank" data-lake-id="uec7704b3" id="uec7704b3"><span data-lake-id="ub3a196e8" id="ub3a196e8">macOS Ventura 13.7.5</span></a></p></td></tr><tr data-lake-id="u7cc1b038" id="u7cc1b038"><td data-lake-id="uc11a1228" id="uc11a1228" style="background-color: rgb(248, 248, 248)"><p data-lake-id="u9211dd9f" id="u9211dd9f" style="text-align: left"><span data-lake-id="u213cb521" id="u213cb521" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24137</span></p></td><td data-lake-id="ufad710e9" id="ufad710e9" style="background-color: rgb(248, 248, 248)"><p data-lake-id="u3abb2084" id="u3abb2084" style="text-align: left"><span data-lake-id="u44c7f335" id="u44c7f335" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-843: Access of Resource Using Incompatible Type (‘Type Confusion’)</span></p></td><td data-lake-id="u8abea2d6" id="u8abea2d6" style="background-color: rgb(248, 248, 248)"><p data-lake-id="u0f90cad0" id="u0f90cad0" style="text-align: left"><a href="https://support.apple.com/en-us/122069" target="_blank" data-lake-id="u13c40b68" id="u13c40b68"><span data-lake-id="u9b69baf7" id="u9b69baf7">macOS 14.7.3</span></a></p><p data-lake-id="ube8fb745" id="ube8fb745" style="text-align: left"><a href="https://support.apple.com/en-us/122073" target="_blank" data-lake-id="u8f30d650" id="u8f30d650"><span data-lake-id="ua25c892f" id="ua25c892f">visionOS 2.3</span></a></p><p data-lake-id="u40e43a8e" id="u40e43a8e" style="text-align: left"><a href="https://support.apple.com/en-us/122072" target="_blank" data-lake-id="u65199fad" id="u65199fad"><span data-lake-id="u29529646" id="u29529646">tvOS 18.3</span></a></p><p data-lake-id="u804b1d2a" id="u804b1d2a" style="text-align: left"><a href="https://support.apple.com/en-us/122068" target="_blank" data-lake-id="u5c53cfbb" id="u5c53cfbb"><span data-lake-id="u4fe28c15" id="u4fe28c15">macOS 15.3</span></a></p><p data-lake-id="u4b5af81b" id="u4b5af81b" style="text-align: left"><a href="https://support.apple.com/en-us/122067" target="_blank" data-lake-id="ub383f6f5" id="ub383f6f5"><span data-lake-id="u23b8bd57" id="u23b8bd57">iPadOS 17.7.4</span></a></p><p data-lake-id="uc747a033" id="uc747a033" style="text-align: left"><a href="https://support.apple.com/en-us/122066" target="_blank" data-lake-id="u8373d0b4" id="u8373d0b4"><span data-lake-id="uaccd9a34" id="uaccd9a34">iOS 18.3 and iPadOS 18.3</span></a></p></td></tr><tr data-lake-id="ub88f4e90" id="ub88f4e90"><td data-lake-id="ufc07d752" id="ufc07d752"><p data-lake-id="uc7ef7ce3" id="uc7ef7ce3" style="text-align: left"><span data-lake-id="uddecfbf6" id="uddecfbf6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-31197 (potential RCE)</span></p></td><td data-lake-id="ua8e9694e" id="ua8e9694e"><p data-lake-id="u7fa1edb7" id="u7fa1edb7" style="text-align: left"><span data-lake-id="ua386f969" id="ua386f969" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-416: Use After Free</span></p></td><td data-lake-id="uae7b711e" id="uae7b711e"><p data-lake-id="ubc0f8403" id="ubc0f8403" style="text-align: left"><a href="https://support.apple.com/en-us/122377" target="_blank" data-lake-id="ufb4ec4a3" id="ufb4ec4a3"><span data-lake-id="ucc246e3f" id="ucc246e3f">tvOS 18.4</span></a></p><p data-lake-id="u0d51c4dd" id="u0d51c4dd" style="text-align: left"><a href="https://support.apple.com/en-us/122371" target="_blank" data-lake-id="ubcaf51f6" id="ubcaf51f6"><span data-lake-id="u9c639eb8" id="u9c639eb8">iOS 18.4 and iPadOS 18.4</span></a></p><p data-lake-id="u79e7f953" id="u79e7f953" style="text-align: left"><a href="https://support.apple.com/en-us/122373" target="_blank" data-lake-id="u2fea19c4" id="u2fea19c4"><span data-lake-id="u9e3a5572" id="u9e3a5572">macOS Sequoia 15.4</span></a></p><p data-lake-id="ud83ddf04" id="ud83ddf04" style="text-align: left"><a href="https://support.apple.com/en-us/122378" target="_blank" data-lake-id="u42009dfe" id="u42009dfe"><span data-lake-id="ufbee54fe" id="ufbee54fe">visionOS 2.4</span></a></p><p data-lake-id="u399d5e2a" id="u399d5e2a" style="text-align: left"><a href="https://support.apple.com/en-us/122374" target="_blank" data-lake-id="u1c348ec5" id="u1c348ec5"><span data-lake-id="u326011b4" id="u326011b4">macOS Sonoma 14.7.5</span></a></p><p data-lake-id="ud54a31f2" id="ud54a31f2" style="text-align: left"><a href="https://support.apple.com/en-us/122375" target="_blank" data-lake-id="uc21a654f" id="uc21a654f"><span data-lake-id="u63492b27" id="u63492b27">macOS Ventura 13.7.5</span></a></p><p data-lake-id="uf3272471" id="uf3272471" style="text-align: left"><a href="https://support.apple.com/en-us/122372" target="_blank" data-lake-id="uba3589da" id="uba3589da"><span data-lake-id="u4bda8ef1" id="u4bda8ef1">iPadOS 17.7.6</span></a></p></td></tr></tbody></table><p data-lake-id="ubfb7ffd6" id="ubfb7ffd6"><strong><span data-lake-id="u586951b2" id="u586951b2" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">本地任意文件读取</span></strong></p><p data-lake-id="uacdaaabe" id="uacdaaabe"><span data-lake-id="uc6554bdd" id="uc6554bdd" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">另一个漏洞允许本地用户读取属于其他用户的文件。利用此漏洞，攻击者可以读取敏感数据、提取凭据，或者潜在地控制具有更高权限的进程。</span></p><table data-lake-id="a6QS0" id="a6QS0" class="lake-table" style="width: 750px"><colgroup><col width="250"><col width="250"><col width="250"></colgroup><tbody><tr data-lake-id="u7113e363" id="u7113e363"><td data-lake-id="ue6f687ed" id="ue6f687ed"><p data-lake-id="u15aa8c32" id="u15aa8c32" style="text-align: left"><strong><span data-lake-id="u832cf801" id="u832cf801" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE</span></strong></p></td><td data-lake-id="u06647e62" id="u06647e62"><p data-lake-id="u930c87c2" id="u930c87c2" style="text-align: left"><strong><span data-lake-id="u07bb2545" id="u07bb2545" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE</span></strong></p></td><td data-lake-id="uef204093" id="uef204093"><p data-lake-id="ubee3067e" id="ubee3067e" style="text-align: left"><strong><span data-lake-id="u02fea67c" id="u02fea67c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">影响范围&amp;公告</span></strong></p></td></tr><tr data-lake-id="u1a938ce8" id="u1a938ce8"><td data-lake-id="u0f866731" id="u0f866731"><p data-lake-id="u622f8113" id="u622f8113" style="text-align: left"><span data-lake-id="u47f18c3c" id="u47f18c3c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24270 (Group)</span></p></td><td data-lake-id="u4725f513" id="u4725f513"><p data-lake-id="ud5c20fed" id="ud5c20fed" style="text-align: left"><span data-lake-id="ue489e1fb" id="ue489e1fb" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-59: Improper Link Resolution Before File Access</span></p></td><td data-lake-id="u20674ec3" id="u20674ec3"><p data-lake-id="ue68a9cc4" id="ue68a9cc4" style="text-align: left"><a href="https://support.apple.com/en-us/122377" target="_blank" data-lake-id="ubda02df6" id="ubda02df6"><span data-lake-id="u9672f487" id="u9672f487">tvOS 18.4</span></a></p><p data-lake-id="u48d7c8ea" id="u48d7c8ea" style="text-align: left"><a href="https://support.apple.com/en-us/122371" target="_blank" data-lake-id="ue121ca89" id="ue121ca89"><span data-lake-id="u93f9113c" id="u93f9113c">iOS 18.4 and iPadOS 18.4</span></a></p><p data-lake-id="u7bb28dad" id="u7bb28dad" style="text-align: left"><a href="https://support.apple.com/en-us/122372" target="_blank" data-lake-id="ub2d996d4" id="ub2d996d4"><span data-lake-id="u1315ce89" id="u1315ce89">iPadOS 17.7.6</span></a></p><p data-lake-id="uf07cdcca" id="uf07cdcca" style="text-align: left"><a href="https://support.apple.com/en-us/122373" target="_blank" data-lake-id="udac7ad38" id="udac7ad38"><span data-lake-id="ua36e11ab" id="ua36e11ab">macOS Sequoia 15.4</span></a></p><p data-lake-id="u672f272b" id="u672f272b" style="text-align: left"><a href="https://support.apple.com/en-us/122378" target="_blank" data-lake-id="uf77ccbc7" id="uf77ccbc7"><span data-lake-id="u125128dc" id="u125128dc">visionOS 2.4</span></a></p><p data-lake-id="u71335e30" id="u71335e30" style="text-align: left"><a href="https://support.apple.com/en-us/122374" target="_blank" data-lake-id="ubd3c039f" id="ubd3c039f"><span data-lake-id="ud3f4543e" id="ud3f4543e">macOS Sonoma 14.7.5</span></a></p><p data-lake-id="u604054ea" id="u604054ea" style="text-align: left"><a href="https://support.apple.com/en-us/122375" target="_blank" data-lake-id="ucb648dc4" id="ucb648dc4"><span data-lake-id="ud2c0888b" id="ud2c0888b">macOS Ventura 13.7.5</span></a></p></td></tr></tbody></table><p data-lake-id="ue5318f11" id="ue5318f11"><strong><span data-lake-id="ua88eceb7" id="ua88eceb7" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">敏感信息泄露</span></strong></p><p data-lake-id="u9b8558ee" id="u9b8558ee"><span data-lake-id="u57811b6c" id="u57811b6c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">另一个关键漏洞可能导致敏感数据在网络上暴露。该漏洞将敏感的日志数据暴露给网络上的任何用户，使攻击者能够识别设备并获取关于用户和设备的敏感信息。</span></p><p data-lake-id="u5e63cd99" id="u5e63cd99"><strong><span data-lake-id="u0242a30b" id="u0242a30b" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">可用于获取敏感数据的漏洞：</span></strong></p><table data-lake-id="k1WCk" id="k1WCk" class="lake-table" style="width: 750px"><colgroup><col width="250"><col width="250"><col width="250"></colgroup><tbody><tr data-lake-id="uae05e197" id="uae05e197"><td data-lake-id="ud052377e" id="ud052377e"><p data-lake-id="ue40a11d0" id="ue40a11d0" style="text-align: left"><strong><span data-lake-id="u66f1bda8" id="u66f1bda8" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE</span></strong></p></td><td data-lake-id="u3a363859" id="u3a363859"><p data-lake-id="uade94144" id="uade94144" style="text-align: left"><strong><span data-lake-id="u5bcb643a" id="u5bcb643a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE</span></strong></p></td><td data-lake-id="u7ba626e2" id="u7ba626e2"><p data-lake-id="ufc83d69f" id="ufc83d69f" style="text-align: left"><strong><span data-lake-id="u3d6197b3" id="u3d6197b3" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">影响范围&amp;公告</span></strong></p></td></tr><tr data-lake-id="u3b4ccfe5" id="u3b4ccfe5"><td data-lake-id="u6d1be726" id="u6d1be726"><p data-lake-id="ue32db2d0" id="ue32db2d0" style="text-align: left"><span data-lake-id="u4bb203f0" id="u4bb203f0" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24270 (Group)</span></p></td><td data-lake-id="u0f0ec3ee" id="u0f0ec3ee"><p data-lake-id="ua446c7c4" id="ua446c7c4" style="text-align: left"><span data-lake-id="ue3f51ead" id="ue3f51ead" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-200: Exposure of Sensitive Information to an Unauthorized Actor</span></p></td><td data-lake-id="u469a5082" id="u469a5082"><p data-lake-id="u79d5ef6e" id="u79d5ef6e" style="text-align: left"><a href="https://support.apple.com/en-us/122377" target="_blank" data-lake-id="u4df07f32" id="u4df07f32"><span data-lake-id="u47e8e450" id="u47e8e450">tvOS 18.4</span></a></p><p data-lake-id="u76624240" id="u76624240" style="text-align: left"><a href="https://support.apple.com/en-us/122371" target="_blank" data-lake-id="ua34d4e46" id="ua34d4e46"><span data-lake-id="ub6400ed8" id="ub6400ed8">iOS 18.4 and iPadOS 18.4</span></a></p><p data-lake-id="uefd23297" id="uefd23297" style="text-align: left"><a href="https://support.apple.com/en-us/122372" target="_blank" data-lake-id="u943cb3ea" id="u943cb3ea"><span data-lake-id="u9572cd00" id="u9572cd00">iPadOS 17.7.6</span></a></p><p data-lake-id="u3853e581" id="u3853e581" style="text-align: left"><a href="https://support.apple.com/en-us/122373" target="_blank" data-lake-id="u459daaea" id="u459daaea"><span data-lake-id="uf2d27a16" id="uf2d27a16">macOS Sequoia 15.4</span></a></p><p data-lake-id="ub95ad7d1" id="ub95ad7d1" style="text-align: left"><a href="https://support.apple.com/en-us/122378" target="_blank" data-lake-id="uaec11d91" id="uaec11d91"><span data-lake-id="uba0bdc64" id="uba0bdc64">visionOS 2.4</span></a></p><p data-lake-id="u4b6893b5" id="u4b6893b5" style="text-align: left"><a href="https://support.apple.com/en-us/122374" target="_blank" data-lake-id="u298681c1" id="u298681c1"><span data-lake-id="uaafc0020" id="uaafc0020">macOS Sonoma 14.7.5</span></a></p><p data-lake-id="uf1a0c5df" id="uf1a0c5df" style="text-align: left"><a href="https://support.apple.com/en-us/122375" target="_blank" data-lake-id="ua7020a39" id="ua7020a39"><span data-lake-id="u85e63493" id="u85e63493">macOS Ventura 13.7.5</span></a></p></td></tr></tbody></table><h3 data-lake-id="qlmOy" id="qlmOy"><strong><span data-lake-id="u200f4ac2" id="u200f4ac2" style="color: rgb(51, 51, 51)">其他漏洞</span></strong></h3><p data-lake-id="u25050af3" id="u25050af3"><span data-lake-id="u4bb1ff6c" id="u4bb1ff6c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">以下漏洞使攻击者能够执行多种不同的操作，例如拒绝服务（DoS）。由于与AirBorne相关的CVE数量较多，因此未能对潜在的可利用性进行深入研究。</span></p><table data-lake-id="ZB5vE" id="ZB5vE" class="lake-table" style="width: 750px"><colgroup><col width="250"><col width="250"><col width="250"></colgroup><tbody><tr data-lake-id="ufb088e84" id="ufb088e84"><td data-lake-id="u7cdaf0d8" id="u7cdaf0d8"><p data-lake-id="u74be0aee" id="u74be0aee" style="text-align: left"><strong><span data-lake-id="ua1401c49" id="ua1401c49" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE</span></strong></p></td><td data-lake-id="u9b24f504" id="u9b24f504"><p data-lake-id="ud17337e8" id="ud17337e8" style="text-align: left"><strong><span data-lake-id="ud3c54062" id="ud3c54062" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE</span></strong></p></td><td data-lake-id="u1b884b52" id="u1b884b52"><p data-lake-id="u9e69fd68" id="u9e69fd68" style="text-align: left"><strong><span data-lake-id="u7f8b3555" id="u7f8b3555" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">影响范围&amp;公告</span></strong></p></td></tr><tr data-lake-id="u97eec2fe" id="u97eec2fe"><td data-lake-id="u055f495d" id="u055f495d"><p data-lake-id="u44f55a6c" id="u44f55a6c" style="text-align: left"><span data-lake-id="u36d6acb6" id="u36d6acb6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24177</span></p></td><td data-lake-id="u7a1a5857" id="u7a1a5857"><p data-lake-id="u82da40ac" id="u82da40ac" style="text-align: left"><span data-lake-id="u6cc2084a" id="u6cc2084a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-476: NULL Pointer Dereference</span></p></td><td data-lake-id="u4bd22876" id="u4bd22876"><p data-lake-id="ud7b26555" id="ud7b26555" style="text-align: left"><a href="https://support.apple.com/en-us/122068" target="_blank" data-lake-id="ucd5ef9e3" id="ucd5ef9e3"><span data-lake-id="ufe739bc5" id="ufe739bc5">macOS Sequoia 15.3</span></a></p><p data-lake-id="u927d028a" id="u927d028a" style="text-align: left"><a href="https://support.apple.com/en-us/122066" target="_blank" data-lake-id="u257b9c61" id="u257b9c61"><span data-lake-id="ubcfb957f" id="ubcfb957f">iOS 18.3 and iPadOS 18.3</span></a></p></td></tr><tr data-lake-id="u6a9ee3c6" id="u6a9ee3c6"><td data-lake-id="u43f3c412" id="u43f3c412" style="background-color: rgb(248, 248, 248)"><p data-lake-id="u1c3648d5" id="u1c3648d5" style="text-align: left"><span data-lake-id="u79eea470" id="u79eea470" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24131</span></p></td><td data-lake-id="u9a6f5d13" id="u9a6f5d13" style="background-color: rgb(248, 248, 248)"><p data-lake-id="u8e565b1c" id="u8e565b1c" style="text-align: left"><span data-lake-id="u39f3a02a" id="u39f3a02a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-230: Improper Handling of Missing Values</span></p></td><td data-lake-id="u7fe57972" id="u7fe57972" style="background-color: rgb(248, 248, 248)"><p data-lake-id="ufa645874" id="ufa645874" style="text-align: left"><a href="https://support.apple.com/en-us/122073" target="_blank" data-lake-id="u53a92ee4" id="u53a92ee4"><span data-lake-id="uc47ba979" id="uc47ba979">visionOS 2.3</span></a></p><p data-lake-id="u33eb7690" id="u33eb7690" style="text-align: left"><a href="https://support.apple.com/en-us/122072" target="_blank" data-lake-id="u310c843a" id="u310c843a"><span data-lake-id="u8774fb37" id="u8774fb37">tvOS 18.3</span></a></p><p data-lake-id="u6d865626" id="u6d865626" style="text-align: left"><a href="https://support.apple.com/en-us/122068" target="_blank" data-lake-id="u146fdfe2" id="u146fdfe2"><span data-lake-id="u79b01c55" id="u79b01c55">macOS Sequoia 15.3</span></a></p><p data-lake-id="uafc71216" id="uafc71216" style="text-align: left"><a href="https://support.apple.com/en-us/122071" target="_blank" data-lake-id="u6a67d26b" id="u6a67d26b"><span data-lake-id="u3c5373e1" id="u3c5373e1">watchOS 11.3</span></a></p><p data-lake-id="u3ab74b9b" id="u3ab74b9b" style="text-align: left"><a href="https://support.apple.com/en-us/122066" target="_blank" data-lake-id="ued5e1aee" id="ued5e1aee"><span data-lake-id="u705a5723" id="u705a5723">iOS 18.3 and iPadOS 18.3</span></a></p></td></tr><tr data-lake-id="uca560eb7" id="uca560eb7"><td data-lake-id="ud7bfbf0c" id="ud7bfbf0c"><p data-lake-id="u5708fd21" id="u5708fd21" style="text-align: left"><span data-lake-id="u206df4a4" id="u206df4a4" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24129</span></p></td><td data-lake-id="ub591aede" id="ub591aede"><p data-lake-id="ub4112f7a" id="ub4112f7a" style="text-align: left"><span data-lake-id="u0651525c" id="u0651525c" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-843: Access of Resource Using Incompatible Type (‘Type Confusion’)</span></p></td><td data-lake-id="u880a5786" id="u880a5786"><p data-lake-id="ue004ecec" id="ue004ecec" style="text-align: left"><a href="https://support.apple.com/en-us/122073" target="_blank" data-lake-id="ub0e6f92f" id="ub0e6f92f"><span data-lake-id="u44556d5e" id="u44556d5e">visionOS 2.3</span></a></p><p data-lake-id="udf1a156f" id="udf1a156f" style="text-align: left"><a href="https://support.apple.com/en-us/122072" target="_blank" data-lake-id="u13beb501" id="u13beb501"><span data-lake-id="ub88f036c" id="ub88f036c">tvOS 18.3</span></a></p><p data-lake-id="ub576e9ce" id="ub576e9ce" style="text-align: left"><a href="https://support.apple.com/en-us/122068" target="_blank" data-lake-id="u63bd5521" id="u63bd5521"><span data-lake-id="ubee4dd3c" id="ubee4dd3c">macOS Sequoia 15.3</span></a></p><p data-lake-id="u31f1f952" id="u31f1f952" style="text-align: left"><a href="https://support.apple.com/en-us/122071" target="_blank" data-lake-id="u7f05c3d6" id="u7f05c3d6"><span data-lake-id="u30275139" id="u30275139">watchOS 11.3</span></a></p><p data-lake-id="u11a0ae0e" id="u11a0ae0e" style="text-align: left"><a href="https://support.apple.com/en-us/122066" target="_blank" data-lake-id="ue26d55b3" id="ue26d55b3"><span data-lake-id="ue7b56cb7" id="ue7b56cb7">iOS 18.3 and iPadOS 18.3</span></a></p></td></tr><tr data-lake-id="ubd5e3e2d" id="ubd5e3e2d"><td data-lake-id="u2ba6df54" id="u2ba6df54" style="background-color: rgb(248, 248, 248)"><p data-lake-id="ueafa10a5" id="ueafa10a5" style="text-align: left"><span data-lake-id="uef22072b" id="uef22072b" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24251</span></p></td><td data-lake-id="u39f20fa3" id="u39f20fa3" style="background-color: rgb(248, 248, 248)"><p data-lake-id="uff39e80d" id="uff39e80d" style="text-align: left"><span data-lake-id="u05020b52" id="u05020b52" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-476: NULL Pointer Dereference</span></p></td><td data-lake-id="u7ddde6d5" id="u7ddde6d5" style="background-color: rgb(248, 248, 248)"><p data-lake-id="uc5a3bdec" id="uc5a3bdec" style="text-align: left"><a href="https://support.apple.com/en-us/122371" target="_blank" data-lake-id="u02c0deed" id="u02c0deed"><span data-lake-id="u36570343" id="u36570343">iOS 18.4 and iPadOS 18.4</span></a></p><p data-lake-id="u626eb17a" id="u626eb17a" style="text-align: left"><a href="https://support.apple.com/en-us/122372" target="_blank" data-lake-id="u366cd446" id="u366cd446"><span data-lake-id="u70d574f8" id="u70d574f8">iPadOS 17.7.6</span></a></p><p data-lake-id="ub741e7f2" id="ub741e7f2" style="text-align: left"><a href="https://support.apple.com/en-us/122373" target="_blank" data-lake-id="uc423513b" id="uc423513b"><span data-lake-id="u163ee3ef" id="u163ee3ef">macOS Sequoia 15.4</span></a></p><p data-lake-id="u97082ce1" id="u97082ce1" style="text-align: left"><a href="https://support.apple.com/en-us/122378" target="_blank" data-lake-id="u02588203" id="u02588203"><span data-lake-id="u58697f12" id="u58697f12">visionOS 2.4</span></a></p><p data-lake-id="uf767cdc2" id="uf767cdc2" style="text-align: left"><a href="https://support.apple.com/en-us/122374" target="_blank" data-lake-id="ua9985aa8" id="ua9985aa8"><span data-lake-id="u685b2c28" id="u685b2c28">macOS Sonoma 14.7.5</span></a></p><p data-lake-id="u74a7353a" id="u74a7353a" style="text-align: left"><a href="https://support.apple.com/en-us/122375" target="_blank" data-lake-id="u0b75889e" id="u0b75889e"><span data-lake-id="uf412e811" id="uf412e811">macOS Ventura 13.7.5</span></a></p><p data-lake-id="u967ffddb" id="u967ffddb" style="text-align: left"><a href="https://support.apple.com/en-us/122073" target="_blank" data-lake-id="u254a229c" id="u254a229c"><span data-lake-id="u0f57b360" id="u0f57b360">visionOS 2.3</span></a></p></td></tr><tr data-lake-id="uedebca85" id="uedebca85"><td data-lake-id="u8598f971" id="u8598f971"><p data-lake-id="u9da0d1b9" id="u9da0d1b9" style="text-align: left"><span data-lake-id="ud5d3196e" id="ud5d3196e" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24126</span></p></td><td data-lake-id="u12c0dff0" id="u12c0dff0"><p data-lake-id="u9a7e2ae3" id="u9a7e2ae3" style="text-align: left"><span data-lake-id="uf3ae3052" id="uf3ae3052" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-476: NULL Pointer Dereference</span></p></td><td data-lake-id="ua60b16ca" id="ua60b16ca"><p data-lake-id="u9933d98e" id="u9933d98e" style="text-align: left"><a href="https://support.apple.com/en-us/122072" target="_blank" data-lake-id="u98ce8e85" id="u98ce8e85"><span data-lake-id="u04b6d330" id="u04b6d330">tvOS 18.3</span></a></p><p data-lake-id="ua781ac94" id="ua781ac94" style="text-align: left"><a href="https://support.apple.com/en-us/122068" target="_blank" data-lake-id="udd1e44fc" id="udd1e44fc"><span data-lake-id="u289bea09" id="u289bea09">macOS Sequoia 15.3</span></a></p><p data-lake-id="ub41c2fe3" id="ub41c2fe3" style="text-align: left"><a href="https://support.apple.com/en-us/122071" target="_blank" data-lake-id="u51e86168" id="u51e86168"><span data-lake-id="uf4eab856" id="uf4eab856">watchOS 11.3</span></a></p><p data-lake-id="u91e0ad48" id="u91e0ad48" style="text-align: left"><a href="https://support.apple.com/en-us/122066" target="_blank" data-lake-id="ue29c1589" id="ue29c1589"><span data-lake-id="u3acf76f7" id="u3acf76f7">iOS 18.3 and iPadOS 18.3</span></a></p><p data-lake-id="uf3a041f1" id="uf3a041f1" style="text-align: left"><a href="https://support.apple.com/en-us/122073" target="_blank" data-lake-id="u6cbd6c2b" id="u6cbd6c2b"><span data-lake-id="u7d7d72ed" id="u7d7d72ed">visionOS 2.3</span></a></p></td></tr><tr data-lake-id="u1a4b29e5" id="u1a4b29e5"><td data-lake-id="u52bcab8f" id="u52bcab8f" style="background-color: rgb(248, 248, 248)"><p data-lake-id="ua878ee6c" id="ua878ee6c" style="text-align: left"><span data-lake-id="u66ecf989" id="u66ecf989" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-24179</span></p></td><td data-lake-id="uf8ac01ac" id="uf8ac01ac" style="background-color: rgb(248, 248, 248)"><p data-lake-id="u3143e8cc" id="u3143e8cc" style="text-align: left"><span data-lake-id="uc85f0921" id="uc85f0921" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-476: NULL Pointer Dereference</span></p></td><td data-lake-id="u5ee01f4b" id="u5ee01f4b" style="background-color: rgb(248, 248, 248)"><p data-lake-id="ua03a145b" id="ua03a145b" style="text-align: left"><a href="https://support.apple.com/en-us/122073" target="_blank" data-lake-id="u5145f049" id="u5145f049"><span data-lake-id="u473ef343" id="u473ef343">visionOS 2.3</span></a></p><p data-lake-id="u8a935ce0" id="u8a935ce0" style="text-align: left"><a href="https://support.apple.com/en-us/122072" target="_blank" data-lake-id="u5b7ce586" id="u5b7ce586"><span data-lake-id="ud4813159" id="ud4813159">tvOS 18.3</span></a></p><p data-lake-id="u9b2751a4" id="u9b2751a4" style="text-align: left"><a href="https://support.apple.com/en-us/122068" target="_blank" data-lake-id="u62bdbaad" id="u62bdbaad"><span data-lake-id="u061d4f38" id="u061d4f38">macOS 15.3</span></a></p><p data-lake-id="u554dba11" id="u554dba11" style="text-align: left"><a href="https://support.apple.com/en-us/122372" target="_blank" data-lake-id="u4544965d" id="u4544965d"><span data-lake-id="u084fdebc" id="u084fdebc">iPadOS 17.7.6</span></a></p><p data-lake-id="u3a18abb3" id="u3a18abb3" style="text-align: left"><a href="https://support.apple.com/en-us/122374" target="_blank" data-lake-id="ua8c19d7e" id="ua8c19d7e"><span data-lake-id="u5e8926a5" id="u5e8926a5">macOS 14.7.5</span></a></p><p data-lake-id="uab296b0a" id="uab296b0a" style="text-align: left"><a href="https://support.apple.com/en-us/122066" target="_blank" data-lake-id="ua27b6e1b" id="ua27b6e1b"><span data-lake-id="u2df28be6" id="u2df28be6">iOS 18.3 and iPadOS 18.3</span></a></p><p data-lake-id="u10166027" id="u10166027" style="text-align: left"><a href="https://support.apple.com/en-us/122375" target="_blank" data-lake-id="udfae1ff6" id="udfae1ff6"><span data-lake-id="u4603437a" id="u4603437a">macOS 13.7.5</span></a></p></td></tr><tr data-lake-id="ue9065972" id="ue9065972"><td data-lake-id="ud34e7532" id="ud34e7532"><p data-lake-id="u1a843c4b" id="u1a843c4b" style="text-align: left"><span data-lake-id="u9903fd3a" id="u9903fd3a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-31203</span></p></td><td data-lake-id="u2cdf4082" id="u2cdf4082"><p data-lake-id="ucd0dc0e6" id="ucd0dc0e6" style="text-align: left"><span data-lake-id="ub66a4404" id="ub66a4404" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-190: Integer Overflow or Wraparound</span></p></td><td data-lake-id="udb2ab210" id="udb2ab210"><p data-lake-id="ua5afc596" id="ua5afc596" style="text-align: left"><a href="https://support.apple.com/en-us/122376" target="_blank" data-lake-id="u7fd396d7" id="u7fd396d7"><span data-lake-id="u28707ad2" id="u28707ad2">watchOS 11.4</span></a></p><p data-lake-id="u1e461b09" id="u1e461b09" style="text-align: left"><a href="https://support.apple.com/en-us/122377" target="_blank" data-lake-id="uc117d34f" id="uc117d34f"><span data-lake-id="ua748c7be" id="ua748c7be">tvOS 18.4</span></a></p><p data-lake-id="u4753588b" id="u4753588b" style="text-align: left"><a href="https://support.apple.com/en-us/122371" target="_blank" data-lake-id="u8aba9421" id="u8aba9421"><span data-lake-id="u1c4cd40f" id="u1c4cd40f">iOS 18.4 and iPadOS 18.4</span></a></p><p data-lake-id="u1ec9b29f" id="u1ec9b29f" style="text-align: left"><a href="https://support.apple.com/en-us/122372" target="_blank" data-lake-id="uf3463e44" id="uf3463e44"><span data-lake-id="u09f8a929" id="u09f8a929">iPadOS 17.7.6</span></a></p><p data-lake-id="uc0e03283" id="uc0e03283" style="text-align: left"><a href="https://support.apple.com/en-us/122373" target="_blank" data-lake-id="u50b43645" id="u50b43645"><span data-lake-id="u55b2820c" id="u55b2820c">macOS Sequoia 15.4</span></a></p><p data-lake-id="u0e958219" id="u0e958219" style="text-align: left"><a href="https://support.apple.com/en-us/122378" target="_blank" data-lake-id="u5474ca26" id="u5474ca26"><span data-lake-id="ud42dcf59" id="ud42dcf59">visionOS 2.4</span></a></p><p data-lake-id="ua1b100d2" id="ua1b100d2" style="text-align: left"><a href="https://support.apple.com/en-us/122374" target="_blank" data-lake-id="u8e3f2df7" id="u8e3f2df7"><span data-lake-id="ud808fe3e" id="ud808fe3e">macOS Sonoma 14.7.5</span></a></p></td></tr><tr data-lake-id="u7e1d3ef4" id="u7e1d3ef4"><td data-lake-id="u33c3fc4e" id="u33c3fc4e" style="background-color: rgb(248, 248, 248)"><p data-lake-id="uec466689" id="uec466689" style="text-align: left"><span data-lake-id="ua84a3710" id="ua84a3710" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-30445 (group of 2 Type Confusion vulnerabilities)</span></p></td><td data-lake-id="u3e99d6dc" id="u3e99d6dc" style="background-color: rgb(248, 248, 248)"><p data-lake-id="ua9b8f90f" id="ua9b8f90f" style="text-align: left"><span data-lake-id="u38f1cb5b" id="u38f1cb5b" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-843: Access of Resource Using Incompatible Type (‘Type Confusion’)</span></p></td><td data-lake-id="ue5498265" id="ue5498265" style="background-color: rgb(248, 248, 248)"><p data-lake-id="uee132016" id="uee132016" style="text-align: left"><a href="https://support.apple.com/en-us/122377" target="_blank" data-lake-id="uf1d97cdd" id="uf1d97cdd"><span data-lake-id="u8360365e" id="u8360365e">tvOS 18.4</span></a></p><p data-lake-id="u90224a30" id="u90224a30" style="text-align: left"><a href="https://support.apple.com/en-us/122371" target="_blank" data-lake-id="u832a5886" id="u832a5886"><span data-lake-id="ue637651b" id="ue637651b">iOS 18.4 and iPadOS 18.4</span></a></p><p data-lake-id="u2242f2df" id="u2242f2df" style="text-align: left"><a href="https://support.apple.com/en-us/122372" target="_blank" data-lake-id="u343e1cca" id="u343e1cca"><span data-lake-id="uf7f0f871" id="uf7f0f871">iPadOS 17.7.6</span></a></p><p data-lake-id="u5f4bc8f0" id="u5f4bc8f0" style="text-align: left"><a href="https://support.apple.com/en-us/122373" target="_blank" data-lake-id="ud4f52797" id="ud4f52797"><span data-lake-id="udfab3c24" id="udfab3c24">macOS Sequoia 15.4</span></a></p><p data-lake-id="u4118716c" id="u4118716c" style="text-align: left"><a href="https://support.apple.com/en-us/122378" target="_blank" data-lake-id="u9049af1d" id="u9049af1d"><span data-lake-id="u29fd9c08" id="u29fd9c08">visionOS 2.4</span></a></p><p data-lake-id="ue6263f81" id="ue6263f81" style="text-align: left"><a href="https://support.apple.com/en-us/122374" target="_blank" data-lake-id="ud01b683a" id="ud01b683a"><span data-lake-id="u6b13c43a" id="u6b13c43a">macOS Sonoma 14.7.5</span></a></p><p data-lake-id="u123fa2bb" id="u123fa2bb" style="text-align: left"><a href="https://support.apple.com/en-us/122375" target="_blank" data-lake-id="u45e61c71" id="u45e61c71"><span data-lake-id="u6f00238d" id="u6f00238d">macOS Ventura 13.7.5</span></a></p></td></tr><tr data-lake-id="u19b75d28" id="u19b75d28"><td data-lake-id="u11051aa0" id="u11051aa0"><p data-lake-id="ue5218a7d" id="ue5218a7d" style="text-align: left"><span data-lake-id="udf30a053" id="udf30a053" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CVE-2025-31202</span></p></td><td data-lake-id="u6cc16f8d" id="u6cc16f8d"><p data-lake-id="uf41ec6c2" id="uf41ec6c2" style="text-align: left"><span data-lake-id="uf83682a6" id="uf83682a6" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-230: Improper Handling of Missing Values</span></p></td><td data-lake-id="ubf1b675d" id="ubf1b675d"><p data-lake-id="u845a03d0" id="u845a03d0" style="text-align: left"><a href="https://support.apple.com/en-us/122377" target="_blank" data-lake-id="u6ba7a351" id="u6ba7a351"><span data-lake-id="u4180d839" id="u4180d839">tvOS 18.4</span></a></p><p data-lake-id="ud6783ad7" id="ud6783ad7" style="text-align: left"><a href="https://support.apple.com/en-us/122371" target="_blank" data-lake-id="ua526f239" id="ua526f239"><span data-lake-id="uecaa63f2" id="uecaa63f2">iOS 18.4 and iPadOS 18.4</span></a></p><p data-lake-id="u351883c3" id="u351883c3" style="text-align: left"><a href="https://support.apple.com/en-us/122373" target="_blank" data-lake-id="uf1e00ba6" id="uf1e00ba6"><span data-lake-id="u1a262472" id="u1a262472">macOS Sequoia 15.4</span></a></p><p data-lake-id="u1df4729f" id="u1df4729f" style="text-align: left"><a href="https://support.apple.com/en-us/122378" target="_blank" data-lake-id="u09d0efe7" id="u09d0efe7"><span data-lake-id="u8caa5d19" id="u8caa5d19">visionOS 2.4</span></a></p></td></tr><tr data-lake-id="u17e587b8" id="u17e587b8"><td data-lake-id="ud16c367a" id="ud16c367a" style="background-color: rgb(248, 248, 248)"><p data-lake-id="uf23d6b43" id="uf23d6b43" style="text-align: left"><span data-lake-id="u6af91668" id="u6af91668" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">Internal Issue #12 (remote user logout)</span></p></td><td data-lake-id="ua099de11" id="ua099de11" style="background-color: rgb(248, 248, 248)"><p data-lake-id="ue28a7c7b" id="ue28a7c7b" style="text-align: left"><span data-lake-id="u1ff4dd7a" id="u1ff4dd7a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-400: Uncontrolled Resource Consumption</span></p></td><td data-lake-id="u6649abcc" id="u6649abcc" style="background-color: rgb(248, 248, 248)"><p data-lake-id="u37150350" id="u37150350" style="text-align: left"><span data-lake-id="u7f0b9633" id="u7f0b9633" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">—</span></p></td></tr><tr data-lake-id="u22c52103" id="u22c52103"><td data-lake-id="uac84e9a4" id="uac84e9a4"><p data-lake-id="u3973b868" id="u3973b868" style="text-align: left"><span data-lake-id="ud33de8bf" id="ud33de8bf" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">Internal Issue #6</span></p></td><td data-lake-id="u20f18a4e" id="u20f18a4e"><p data-lake-id="udbe86a21" id="udbe86a21" style="text-align: left"><span data-lake-id="ua3de4620" id="ua3de4620" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">CWE-476: NULL Pointer Dereference</span></p></td><td data-lake-id="u4e117ce1" id="u4e117ce1"><p data-lake-id="uf1c9afaa" id="uf1c9afaa" style="text-align: left"><span data-lake-id="u96332f6f" id="u96332f6f" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">—</span></p></td></tr></tbody></table><ul list="uc54048e9"><li fid="u1d68beed" data-lake-id="ufb12399f" id="ufb12399f"><span data-lake-id="u84ef742d" id="u84ef742d" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">虽然上述漏洞可能会产生各种影响，但崩溃AirPlay服务器为中间人攻击提供了机会。例如，考虑一下即将开始的董事会议。首席执行官希望将会议通过AirPlay投射到办公室的电视上。攻击者可以利用其中一个DoS漏洞：</span></li></ul><ul list="uc54048e9" data-lake-indent="1"><li fid="u7ce36251" data-lake-id="u89243dfe" id="u89243dfe"><span data-lake-id="u1707f171" id="u1707f171" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">利用其中一个DoS漏洞使电视的AirPlay接收器崩溃</span></li><li fid="u7ce36251" data-lake-id="uc6fba868" id="uc6fba868"><span data-lake-id="u1e856e35" id="u1e856e35" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">使用mDNS伪造电视在网络上的身份</span></li><li fid="u7ce36251" data-lake-id="u6eee3892" id="u6eee3892"><span data-lake-id="uf8415b74" id="uf8415b74" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">等待首席执行官开始将内容流式传输到伪造的AirPlay服务器</span></li><li fid="u7ce36251" data-lake-id="ue71aed32" id="ue71aed32"><span data-lake-id="u7e09bd16" id="u7e09bd16" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">将首席执行官的流从伪造的服务器中转发到真实的电视</span></li><li fid="u7ce36251" data-lake-id="u552c9f48" id="u552c9f48"><span data-lake-id="u91769a35" id="u91769a35" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">捕获并记录整个会议内容，从被拦截的流中获取</span></li></ul><h3 data-lake-id="E6MLS" id="E6MLS"><strong><span data-lake-id="u6817e66d" id="u6817e66d" style="color: rgb(51, 51, 51)">漏洞缓解</span></strong></h3><p data-lake-id="u4d14e57d" id="u4d14e57d"><span data-lake-id="uc59964e2" id="uc59964e2" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">对于组织来说，确保所有公司Apple设备和其他支持AirPlay的设备立即更新到最新的软件版本至关重要。安全领导者还需要向员工明确传达，所有支持AirPlay的个人设备也需要立即更新。</span></p><h2 data-lake-id="ZkWLo" id="ZkWLo"><strong><span data-lake-id="u9816290d" id="u9816290d" style="color: rgb(51, 51, 51)">建议修复步骤</span></strong></h2><ul list="u8036cc9d" data-lake-indent="1"><li fid="u2f6efe48" data-lake-id="u89be7591" id="u89be7591"><strong><span data-lake-id="u9d70660d" id="u9d70660d" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">建议用户更新设备</span></strong><span data-lake-id="u5a905575" id="u5a905575" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">，以减轻潜在的安全风险。</span><strong><span data-lake-id="u4dced5a2" id="u4dced5a2" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">‍</span></strong></li><li fid="u2f6efe48" data-lake-id="u2e624194" id="u2e624194"><strong><span data-lake-id="u8730e528" id="u8730e528" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">禁用AirPlay接收器</span></strong><span data-lake-id="u77605e55" id="u77605e55" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：如果不使用AirPlay接收器，建议彻底禁用。</span><strong><span data-lake-id="ufcbd4a85" id="ufcbd4a85" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">‍</span></strong></li><li fid="u2f6efe48" data-lake-id="u0765b0fa" id="u0765b0fa"><strong><span data-lake-id="u3c0340dd" id="u3c0340dd" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">限制AirPlay访问</span></strong><span data-lake-id="u758271d7" id="u758271d7" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：创建防火墙规则，仅允许受信任设备访问AirPlay通信（Apple设备上的端口</span><em><span data-lake-id="u9f03f72f" id="u9f03f72f" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">7000</span></em><span data-lake-id="ufe1de6ae" id="ufe1de6ae" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">），增强网络安全性并减少暴露风险。</span></li><li fid="u2f6efe48" data-lake-id="u1ec6c751" id="u1ec6c751"><strong><span data-lake-id="uf05b1b61" id="uf05b1b61" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">限制AirPlay设置</span></strong><span data-lake-id="ue456a7fb" id="ue456a7fb" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">：将“允许AirPlay的设备”更改为“当前用户”。虽然这</span><strong><span data-lake-id="uc631100a" id="uc631100a" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">不能防止</span></strong><span data-lake-id="u4c7c6eb7" id="u4c7c6eb7" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">报告中提到的所有问题，但确实减少了该协议的攻击面。</span></li></ul><p data-lake-id="u7718110c" id="u7718110c"><card type="inline" name="image" value="data:%7B%22src%22%3A%22https%3A%2F%2Fcdn.prod.website-files.com%2F63e8dd453f71270c6845992b%2F67990bb83cc402f28e33df2b_67990b9728bbebc95de1f09f_airplay%252520settings.png%22%2C%22originalType%22%3A%22binary%22%2C%22linkTarget%22%3A%22_blank%22%2C%22from%22%3A%22url%22%2C%22originWidth%22%3A1418%2C%22originHeight%22%3A904%2C%22ratio%22%3A1%2C%22status%22%3A%22done%22%2C%22style%22%3A%22none%22%2C%22showTitle%22%3Afalse%2C%22title%22%3A%22%22%2C%22rotation%22%3A0%2C%22crop%22%3A%5B0%2C0%2C1%2C1%5D%2C%22id%22%3A%22hkwO7%22%2C%22margin%22%3A%7B%22top%22%3Atrue%2C%22bottom%22%3Atrue%7D%7D"></card></p><p data-lake-id="uc5691163" id="uc5691163"><strong><span data-lake-id="u93d3d08f" id="u93d3d08f" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">AirPlay接收器可以在系统设置中关闭。</span></strong></p><h3 data-lake-id="dEMaW" id="dEMaW"><br></h3><p data-lake-id="ub3b9f634" id="ub3b9f634"><span data-lake-id="uff8eb495" id="uff8eb495" class="lake-fontsize-12" style="color: rgb(51, 51, 51)">参考：</span><a href="https://www.oligo.security/blog/airborne" target="_blank" data-lake-id="u6b15302d" id="u6b15302d"><span data-lake-id="u07f75520" id="u07f75520">https://www.oligo.security/blog/airborne</span></a></p>

打赏我,让我更有动力~

2 条回复   |  直到 7个月前 | 219 次浏览

小瑟斯
发表于 7个月前

PHA+PHNwYW4+5rao55+l6K+G5LqGPC9zcGFuPjwvcD4=

评论列表

  • 加载数据中...

编写评论内容

sechacker
发表于 7个月前

PHA+PHNwYW4+5LmL5YmN6Iu55p6c55qE5ryP5rSe77yM5L+u5aSN55qE55yf5b+rPC9zcGFuPjwvcD4=

评论列表

  • 加载数据中...

编写评论内容
登录后才可发表内容
返回顶部 投诉反馈

© 2016 - 2025 掌控者 All Rights Reserved.