Urgent warning issued to iPhone users to turn off AirPlay

Apple’s AirPlay feature is beloved by many users — but it can leave you vulnerable to hackers.

Experts at the cybersecurity company Oligo identified significant security vulnerabilities in Apple AirPlay, which enable attackers to take control of connected devices sharing the same Wi-Fi network.

AirPlay is a feature that lets users effortlessly stream audio, video, or images from one Apple device to another, or to non-Apple devices that support the protocol.

According to Wired, these 23 security issues, collectively called “AirBorne,” were discovered in both Apple’s AirPlay protocol and the AirPlay Software Development Kit (SDK) utilized by third-party manufacturers to ensure their devices are compatible with AirPlay.

Researchers demonstrated in a video how vulnerabilities can be exposed to hackers by accessing an AirPlay-enabled Bose speaker on the same network and remotely executing a Remote Code Execution (RCE) attack, showing the “AirBorne” logo on the speaker’s display.

They claimed that hackers realistically can use a similar strategy to gain access to devices with microphones for espionage.

Oligo CTO Gal Elbaz told Wired that the total number of exposed devices could potentially be in the millions.

“Because AirPlay is supported in such a wide variety of devices, there are a lot that will take years to patch — or they will never be patched,” Elbaz explained. “And it’s all because of vulnerabilities in one piece of software that affects everything.”


Dangerous Hooded Hacker Breaks into Government Data Servers and Infects Their System with a  Virus. His Hideout Place has Dark Atmosphere, Multiple Displays, Cables Everywhere.
Oligo CTO Gal Elbaz told Wired that the total number of exposed devices could potentially be in the millions. Gorodenkoff – stock.adobe.com

The risks were reported to Apple in the late fall and winter of last year, and Oligo worked with the tech giant for months on fixes before publishing their findings Tuesday.

Apple devices with iOS 18.4, iPadOS 18.4, macOS Ventura 13.7.5, macOS Sonoma 14.7.5, macOS Sequoia 15.4 and visionOS 2.4 had fixes rolled out on March 31.

However, third-party devices that support AirPlay protocol remain vulnerable. The researchers said that manufacturers would need to roll out updates for users to install themselves in order to avoid being exposed to hackers.


Koh Samui, Thailand - March 26, 2018: Man hand holding iPhone X with home screen Control Center. iPhone 10 was created and developed by the Apple inc.
AirPlay allows users to seamlessly stream audio, video or photos from their Apple device to another device. DenPhoto – stock.adobe.com

Apple told Wired that it created patches available for these third-party devices, but it emphasized that there are “limitations” to the attacks that would be possible on AirPlay-enabled devices due to the bugs.

CarPlay-equipped systems are also at risk, the researchers noted, since hackers can carry out an RCE attack if they are near the unit and “the device has a default, predictable, or known Wi-Fi hotspot password.”

According to the report, there are several ways to help protect your device from the threat of hackers:

  • ‍Update your devices: Researchers stressed that devices and other machines that support AirPlay need to be updated immediately to the latest software versions to mitigate potential security risks.
  • Disable AirPlay Receiver: Oligo recommends fully disabling the AirPlay feature when not in use.
  • Only AirPlay to trusted devices: Limit AirPlay communication and stream content to only trusted devices.
  • Restrict AirPlay Settings: Go to Settings > AirPlay & Continuity (or AirPlay & Handoff) and select Current User for the “Allow AirPlay for” option. “While this does not prevent all of the issues mentioned in the report, it does reduce the protocol’s attack surface,” researchers noted.
  • Disable on public Wi-Fi: It’s best to avoid enabling or using AirPlay when on a public Wi-Fi network.

You May Also Like
Our Chicago: Joabe Barbosa completes mission to run every street in city

Chicago Runner Joabe Barbosa Completes Mission to Run Every Street in the City

CHICAGO (WLS) — In August 2024, Joabe Barbosa set out on an…
World Cup security worker Aaron Avery hit, killed near SoFi Stadium in California, remembered through life-saving organ donation

World Cup Security Worker Aaron Avery Struck and Killed Near SoFi Stadium, Honored Through Organ Donation

INGLEWOOD, Calif. — A 22-year-old man who had recently begun working security…
Race Against Hate draws thousands to Evanston to honor Ricky Byrdsong's legacy, Northwestern basketball coach killed in 1999

Thousands Join Evanston Race Against Hate to Honor Legacy of Slain Northwestern Coach Ricky Byrdsong

The annual event pays tribute to Ricky Byrdsong, Northwestern University’s first Black…
World Cup worker, 22, killed while walking home from SoFi Stadium

22-Year-Old World Cup Worker Killed on Walk Home From SoFi Stadium

A 22-year-old SoFi Stadium employee, who was reportedly just two days into…
Adorable doggy fashion show 'Dare to Strut' takes Los Angeles by storm

Los Angeles Dogs Hit the Runway at Adorable Dare to Strut Fashion Show

Paws up! The stars arrived, strutted their stuff, and stole the spotlight…
MMA fighter helps nab Florida university student leader in suspected child predator sting

MMA Fighter Helps Catch Florida University Student Leader in Alleged Child Predator Sting

A South Florida mixed martial arts fighter known for pursuing suspected child…

Mamdani and House Candidates Draw Scrutiny Over Links to Activist Accused of Hamas Support

Mayor Zohran Mamdani and what critics have dubbed his “Hamas slate” of…
EXCLUSIVE: Meet the man Israel chose to be its first-ever ambassador to the Christian world

Israel’s First Ambassador to the Christian World: Meet the Man Behind the Historic Role

Prime Minister Benjamin Netanyahu’s government has created a new diplomatic post aimed…
Goose ‘reeling’ after dad Paul Kueker fell to his death at Madison Square Garden concert — pays tribute in Central Park

Goose Honors Paul Kueker in Central Park After Fatal Fall at Madison Square Garden Concert

Connecticut jam band Goose said they were devastated to learn, just after…
Albanian protesters flood streets demanding prime minister's resignation amid corruption accusations

Albanian Protesters Fill Streets Calling for Prime Minister’s Resignation Over Corruption Allegations

Albanians protest against government corruption Thousands of demonstrators filled the streets of…
JD Vance arrives in Switzerland to launch talks with Iran on its nuclear program

JD Vance Arrives in Switzerland to Open Talks With Iran on Nuclear Program

OBBUERGEN, Switzerland — U.S. Vice President JD Vance arrived in Switzerland on…
Iran's unprecedented 'whole-regime' delegation at US deal talks signals one goal: expert

Iran’s Unprecedented Full-Regime Delegation to U.S. Talks Signals a Singular Aim, Expert Says

The size and makeup of Iran’s delegation at Switzerland’s first round of…