Millions of Apple Airplay-Enabled Devices Can Be Hacked via Wi-Fi

AirPlay Vulnerabilities Expose Millions of Third-Party Devices to Wi-Fi-Based Attacks
Photo: WIRED

AirPlay Vulnerabilities Expose Millions of Third-Party Devices to Wi-Fi-Based Attacks

Researchers from cybersecurity firm Oligo have identified a set of vulnerabilities, collectively named AirBorne, affecting Apple’s AirPlay protocol. These flaws allow hackers on the same Wi-Fi network to execute malicious code on third-party AirPlay-enabled devices like speakers, TVs, and set-top boxes. While Apple has patched vulnerabilities in its own devices through recent updates, tens of millions of third-party devices using Apple’s AirPlay SDK remain at risk due to infrequent security patches. The vulnerabilities could enable attackers to hijack devices, spread malware across networks, or incorporate them into botnets. Many vulnerable devices also include microphones, raising concerns about covert eavesdropping. CarPlay systems in over 800 vehicle models are similarly affected, though exploitation requires physical Bluetooth or USB pairing. Oligo disclosed these flaws to Apple in late 2023, leading to patches for Apple products, but third-party manufacturers often lag in updates. The researchers stress that devices like smart speakers and TVs are particularly vulnerable due to their typically neglected update cycles. Apple emphasizes that attacks require proximity to the target network and that user data on such devices is limited. The findings highlight systemic risks in IoT ecosystems where manufacturers fail to maintain security updates for Apple-certified technologies.

Leave a Reply

Your email address will not be published. Required fields are marked *