CVE-2025-30422
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
30/04/2025
Last modified:
02/04/2026
Description
A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apple:airplay_audio_software_development_kit:*:*:*:*:*:*:*:* | 2.7.1 (excluding) | |
| cpe:2.3:a:apple:airplay_video_software_development_kit:*:*:*:*:*:*:*:* | 3.6.0.126 (excluding) | |
| cpe:2.3:a:apple:carplay_communication_plug-in:*:*:*:*:*:*:*:* | r18.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



