Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/cakescats/airborn-ios-cve-2025-24252
iOS SecurityVulnerability AnalysisForensicsMobile ForensicsDigital ForensicsLearning & EducationIncident ResponseLog Analysis

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
cakescats/airborn-ios-cve-2025-24252

airborn-IOS-CVE-2025-24252

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

View Repository
3381 year agoNot yet reviewed
Share

iOS "Airborne" Vulnerabilities - Log Artifact Extractor

This script is designed to help identify potential traces of the "Airborne" set of vulnerabilities (primarily affecting Apple's AirPlay protocol) by querying iOS system logs from a .logarchive bundle. It automates the execution of several log show commands tailored to find anomalies that could be associated with these vulnerabilities.

Disclaimer: This tool is for informational and investigative purposes only. The presence of log entries matching these queries does not definitively confirm a compromise. Log entries should be analyzed in context. The absence of findings does not guarantee a device is secure. Always ensure your devices are updated to the latest OS versions.

About the Author and Project

This script was developed by Anton Shustikov [email protected] (now is ceo cakescats) as part of the CakesCats project.

CakesCats is an initiative focused on:

  • Information Security Education: Aiming to make cybersecurity concepts more accessible and understandable.
  • Support: Providing free support to activists and individuals facing difficult situations related to digital security.
  • Simple & Clear Products: Developing straightforward tools and resources for digital safety and security.

Anton Shustikov is an information security and fintech consultant with extensive experience in creating security systems. He is the founder of the non-commercial educational project CakesCats and contributes articles to publications like Forbes and "Xakep" magazine. His work often involves investigating digital threats and promoting digital hygiene.

About "Airborne" Vulnerabilities

"Airborne" is a name given to a set of vulnerabilities (discovered by Oligo Security in their original research) affecting Apple's AirPlay protocol and the AirPlay Software Development Kit (SDK). These vulnerabilities can impact a wide range of Apple devices (iPhones, iPads, Macs, Apple TV, etc.) and third-party devices using the AirPlay SDK (e.g., smart speakers, receivers).

Key aspects of "Airborne" type vulnerabilities:

  • Discovery Context: The original "Airborne" research was published by Oligo Security (More details: https://www.oligo.security/blog/airborne). This script is designed to look for general forensic artifacts that could be related to such vulnerabilities.
  • Affected Protocols/Components: Primarily Apple AirPlay, but also related services like Bonjour (mDNS) and rapportd which handles device-to-device communication.
  • Potential Impact: Remote Code Execution (RCE) (including zero-click and potentially wormable variants), Denial of Service (DoS), Access Control List (ACL) bypass, information disclosure, and Man-in-the-Middle (MITM) attacks.
  • CVEs (Contextual Examples): While specific CVE numbers change with each new discovery, the "Airborne" class of vulnerabilities targets flaws in how AirPlay and related network services handle data, pairing, or connections. For example, previous hypothetical discussions for this tool considered CVEs like CVE-2025-24252 (related to mDNS issues) or CVE-2025-24132 (related to buffer overflows in the AirPlay SDK). Users should always refer to specific CVE details and vendor advisories for the vulnerabilities they are investigating.
  • Affected OS Versions (General Guidance): Typically, versions of iOS, iPadOS, macOS, tvOS, and third-party AirPlay SDKs prior to patches released by Apple and respective vendors in response to specific vulnerability disclosures. Always consult Apple's official security updates and vendor advisories for information on patched versions.

How This Tool Works

This script executes a series of log show commands using carefully crafted predicates. These predicates are designed to filter the vast amount of information in iOS system logs to pinpoint potential indicators of compromise or anomalous activity that might be related to "Airborne" type vulnerabilities.

The script looks for:

  • Crashes or errors in critical system processes involved in AirPlay, media streaming, network discovery, and device-to-device communication (e.g., mediaserverd, AirPlayXPCHelper, rapportd, mDNSResponder).
  • Errors specifically logged by the AirPlay subsystem or Bonjour/mDNS services.
  • Anomalous network connection events (e.g., unexpected connection resets, failures to connect) reported by relevant processes.
  • Kernel panics, which can indicate severe system instability potentially caused by an exploit.
  • Suspicious activity related to configuration profiles (as a general post-exploitation vector).
  • Sandbox violation messages, which could indicate an exploit attempting to break out of its restricted environment.

The output of each query is saved into a separate, descriptively named text file within a timestamped results directory, allowing for focused analysis of different types of potential artifacts.

Prerequisites

  1. macOS Environment: The log show utility and this script are intended to be run on macOS.
  2. iOS Log Archive (.logarchive): You need an iOS system log archive (a bundle, which is technically a directory) from the device you intend to analyze. This can typically be obtained via:
    • Xcode: Connect the iOS device to a Mac, open Xcode, go to Window -> Devices and Simulators, select your device, then click "View Device Logs" and "Export".
    • sysdiagnose: Trigger a sysdiagnose on the iPhone (usually by pressing Volume Up + Volume Down + Side button simultaneously, but combinations can vary by model and iOS version). After the sysdiagnose is generated (it can take several minutes), it can be AirDropped to a Mac or accessed when syncing the iPhone with a Mac (often found in Finder under the iPhone's sync location within a .tar.gz file). The .logarchive will be within the extracted sysdiagnose contents.
  3. Bash Shell: The script is written for bash.

Setup and Execution

  1. Save the Script: Save the script code (provided above) as airborne_artifact_extractor.sh (or any other name with a .sh extension).

  2. Make it Executable: Open your Terminal application, navigate to the directory where you saved the script, and run the following command:

    chmod +x airborne_artifact_extractor.sh
    
  3. Check macOS Quarantine Attribute (Important for downloaded scripts): If you downloaded this script from the internet, macOS might quarantine it, which can prevent it from running correctly or at all.

    • To check if the quarantine attribute is set, run:
      xattr airborne_artifact_extractor.sh
      
    • If the output includes com.apple.quarantine, remove this attribute by running:
      xattr -d com.apple.quarantine airborne_artifact_extractor.sh
      

    If you still encounter issues running the script, especially if it's located in a directory like ~/Downloads, ensure that your Terminal application has necessary permissions (e.g., "Full Disk Access" in System Settings -> Privacy & Security) to access the script's location and the log archive.

Troubleshooting Execution Issues

Bad Interpreter or ^M errors (e.g., /bin/bash^M: bad interpreter: No such file or directory)

If you encounter an error like bash: ./your_script_name.sh: /bin/bash^M: bad interpreter: No such file or directory, /usr/bin/env: ‘bash\r’: No such file or directory, or similar messages involving \r or ^M characters when trying to execute the script, it's likely due to Windows-style line endings (CRLF - Carriage Return Line Feed) instead of Unix-style line endings (LF - Line Feed).

Download Tool