Apple issues urgent warning to 1,800,000,000 iPhone users over popular feature

2025-05-06 HaiPress

The security holes involve the use of a common Apple feature (Picture: REUTERS)

Experts have found a flaw in Apple iPhones that lets hackers worm their way into any device.

Oligo Security discovered 23 vulnerabilities in AirPlay,which lets users stream from their iPhone,iPad or MacBook to devices via Wi-Fi.

Gadgets AirPlay works with include Apple TV,HomePod,smart TVs,speakers or receivers.

Two of these security holes allow attackers to infect a device with malware that then spreads to all the other gadgets on the same Wi-Fi network,the computer application company found.

AirPlay,Apple’s wireless-audio standard,had two major flaws hackers could exploit (Picture: Shutterstock/FellowNeko)

Oligo named these weaknesses ‘AirBorne’ as they ‘allow attackers to fully take over devices and use that access as a launchpad for further exploitation’.

These vulnerabilities,with the very catchy names of CVE-2025-24252 and CVE-2025-24132,pave the way for cyber crooks to carry out ‘other sophisticated attacks’,such as espionage or ransomware.

Think hackers executing malicious code to gain control,steal your personal information,eavesdrop on conversations or crash the device.

CarPlay,which combines iPhone programmes,including maps,messages and music,into a single interface,is also impacted,the researchers found.

Attackers could carry out what is called a ‘remote code execution attavck’,so they can deploy malware and steal data.

‘Using the WiFi hotspot in the CarPlay device,an attacker could execute an RCE attack given that they are in close proximity to the CarPlay unit,’ Oligo said.

‘If the device has a default,predictable or known Wi-Fi hotspot password,it is possible to gain access and then execute the RCE.  

Hackers,however,can only exploit these bugs when they are on the same Wi-Fi network as the device they are targeting. 

AirPlay is available on many modern Apple gadgets (Picture: Apple)

As AirPlay works with third-party devices,of which there are tens of millions of,Oligo says iPhones may still be vulnerable if the manufacturer hasn’t updated.

Don’t worry,though. There’s a good chance that your Apple device is shielded from these nasty bugs.

Apple added the necessary patches on April 28 to its March update,iOS 18.4 and iPadOS 18.4,having worked with Oligo to patch it.

This was confirmed on the National Vulnerability Database,where entries for the two bugs say they were fixed with ‘improved memory management’.

Check your phone to see if it’s updated to keep yourself protected.

For peace of mind,only toggle on AirPlay when you need it. When the feature is on,the device is always on the look out for AirPlay signals,making it a viable ‘attack surface’.

Disclaimer: This article is reproduced from other media. The purpose of reprinting is to convey more information. It does not mean that this website agrees with its views and is responsible for its authenticity, and does not bear any legal responsibility. All resources on this site are collected on the Internet. The purpose of sharing is for everyone's learning and reference only. If there is copyright or intellectual property infringement, please leave us a message.

Newest

1The Second Session of the World Chinese Medicine Forum Spring 2026: Masterclass on Clinical Strategies and Case Studies of Special Diathesis Successfully Held

The Second Session of the World Chinese Medicine Forum Spring 2026: Masterclass on Clinical Strategies and Case Studies of Special Diathesis Successfully Held

2The First Session of the World Chinese Medicine Forum Spring 2026: Masterclass on Nine Types of TCM Constitution Identification and Conditioning Successfully Launched

The First Session of the World Chinese Medicine Forum Spring 2026: Masterclass on Nine Types of TCM Constitution Identification and Conditioning Successfully Launched

3Anmrex Formally Submits Singapore MAS License Application: Entering the Substantive Stage of Compliance Admission

Anmrex Formally Submits Singapore MAS License Application: Entering the Substantive Stage of Compliance Admission

4BGI Group Showcases Life Science Innovation Across the Value Chain at the 4th China International Supply Chain Expo

BGI Group Showcases Life Science Innovation Across the Value Chain at the 4th China International Supply Chain Expo

5[The Era of Shareholding: Benefits for Generations] Digital Trade Connect 2026 Member Equity Certificates Usher in a Key Window!

[The Era of Shareholding: Benefits for Generations] Digital Trade Connect 2026 Member Equity Certificates Usher in a Key Window!

6ZTE Server Solutions Highlight AI Infrastructure Progress at ZTE Day Indonesia 2026

ZTE Server Solutions Highlight AI Infrastructure Progress at ZTE Day Indonesia 2026

©copyright2009-2020Fresh life