๐Ÿค–์ •๋ณด๋ณด์•ˆ/๐Ÿ’™๋ธ”๋ฃจํŒ€

[์ •๋ณด] ์• ํ”Œ ๋ํŒ์™• ์ทจ์•ฝ์  Airborne ๊ณต๊ฐœ(0-Click, RCE, CVE-2025-24132)

TwoIceFish 2025. 5. 6. 22:29

 

[๐Ÿšจ์œ„ํ—˜๋‚ด์šฉ]

- Apple AirPlay์˜ "๊ณต์ค‘ ์ „ํŒŒ" ์ œ๋กœํด๋ฆญ RCE ๊ณต๊ฒฉ์œผ๋กœ 23์–ต 5์ฒœ๋งŒ ๋Œ€ ์ด์ƒ์˜ ๊ธฐ๊ธฐ๊ฐ€ Wi-Fi ๊ธฐ๋ฐ˜ ์›๊ฒฉ ํ•˜์ด์žฌํ‚น์— ๋…ธ์ถœ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. Mac, iPhone, CarPlay, ์Šคํ”ผ์ปค, TV ๋“ฑ ๊ณต์œ  ๋„คํŠธ์›Œํฌ์—์„œ ๋ชจ๋‘ ์ทจ์•ฝํ•ฉ๋‹ˆ๋‹ค.

- ์›œ ๊ณต๊ฒฉ ๊ฐ€๋Šฅ. ์•…์šฉ ๊ฐ€๋Šฅ. 

- CVE-2025-24252

- ๊ฐ™์€ ๋„คํŠธ์›Œํฌ์— ์žˆ๊ณ  ์—์–ดํ”Œ๋ ˆ์ด ์—…๋ฐ์ดํŠธ๊ฐ€ ๋˜์–ด์žˆ์ง€ ์•Š๋‹ค๋ฉด ๋‹น์‹  ๋””๋ฐ”์ด์Šค๋Š” ์ทจ์•ฝ์ ์— ๋…ธ์ถœ ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

 

[๐Ÿ”“๋Œ€์‘๋ฐฉ์•ˆ]
- ํŒจ์น˜(iOS/macOS 18.4 ์ด์ƒ).

- AirPlay ๋„๊ธฐ

 

[๋งฅ๋ถํ•ดํ‚น]

https://www.youtube.com/watch?v=ZmOvRLBL3Ys

 

 

[์Šคํ”ผ์ปคํ•ดํ‚น]

https://www.youtube.com/watch?v=vcs5G4JWab8

 

 

[์ž๋™์ฐจํ•ดํ‚น]

https://www.youtube.com/watch?v=eq8bUwFuSUM

 

 

[์ทจ์•ฝ์ ์ƒ์„ธ๋‚ด์šฉ]

https://www.oligo.security/blog/airborne

 

Airborne: Wormable Zero-Click RCE in Apple AirPlay Puts Billions of Devices at Risk | Oligo Security | Oligo Security

Oligo Security reveals AirBorne, a new set of vulnerabilities in Apple’s AirPlay protocol and SDK. Learn how zero-click RCEs, ACL bypasses, and wormable exploits could endanger Apple and IoT devices worldwide — and how to protect yourself.

www.oligo.security

 

[shodan์—์„œ ๋…ธ์ถœ๋œ ์„œ๋น„์Šค ๋ชฉ๋ก]