Researchers at cybersecurity firm Oligo today outlined a series of AirPlay vulnerabilities that impact millions of Apple devices (via Wired) and accessories that connect to Apple devices. While Apple has addressed the flaws in security updates that have come out over the last several months, some third-party devices that support AirPlay remain vulnerable.
Dubbed “Airborne,” the AirPlay vulnerabilities allowed attackers to take control of devices that support AirPlay to spread malware to other devices on any local device that the infected device connects to. An attacker would need to be on the same Wi-Fi network as the intended victim, putting public Wi-Fi spots, businesses, and other high-traffic areas at more risk.
Oligo researchers said that the AirPlay flaws could lead to “sophisticated attacks related to espionage, ransomware, supply-chain attacks, and more.” The vulnerabilities could be used independently or chained together for a “variety of possible attack vectors,” such as Remote Code Execution, user interaction bypass, Denial of Service attacks, Man-in-the-Middle attacks, and more.
Read more at MacRumors.com
