
iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252
This script is designed to help identify potential traces of the "Airborne" set of vulnerabilities (primarily affecting Apple's AirPlay protocol) by querying iOS system logs from a .logarchive bundle. It automates the execution of several log show commands tailored to find anomalies that could be associated with these vulnerabilities.
Disclaimer: This tool is for informational and investigative purposes only. The presence of log entries matching these queries does not definitively confirm a compromise. Log entries should be analyzed in context. The absence of findings does not guarantee a device is secure. Always ensure your devices are updated to the latest OS versions.
This script was developed by Anton Shustikov [email protected] (now is ceo cakescats) as part of the CakesCats project.
CakesCats is an initiative focused on:
Anton Shustikov is an information security and fintech consultant with extensive experience in creating security systems. He is the founder of the non-commercial educational project CakesCats and contributes articles to publications like Forbes and "Xakep" magazine. His work often involves investigating digital threats and promoting digital hygiene.
"Airborne" is a name given to a set of vulnerabilities (discovered by Oligo Security in their original research) affecting Apple's AirPlay protocol and the AirPlay Software Development Kit (SDK). These vulnerabilities can impact a wide range of Apple devices (iPhones, iPads, Macs, Apple TV, etc.) and third-party devices using the AirPlay SDK (e.g., smart speakers, receivers).
Key aspects of "Airborne" type vulnerabilities:
rapportd which handles device-to-device communication.This script executes a series of log show commands using carefully crafted predicates. These predicates are designed to filter the vast amount of information in iOS system logs to pinpoint potential indicators of compromise or anomalous activity that might be related to "Airborne" type vulnerabilities.
The script looks for:
mediaserverd, AirPlayXPCHelper, rapportd, mDNSResponder).The output of each query is saved into a separate, descriptively named text file within a timestamped results directory, allowing for focused analysis of different types of potential artifacts.
log show utility and this script are intended to be run on macOS..logarchive): You need an iOS system log archive (a bundle, which is technically a directory) from the device you intend to analyze. This can typically be obtained via:
sysdiagnose: Trigger a sysdiagnose on the iPhone (usually by pressing Volume Up + Volume Down + Side button simultaneously, but combinations can vary by model and iOS version). After the sysdiagnose is generated (it can take several minutes), it can be AirDropped to a Mac or accessed when syncing the iPhone with a Mac (often found in Finder under the iPhone's sync location within a .tar.gz file). The .logarchive will be within the extracted sysdiagnose contents.bash.Save the Script:
Save the script code (provided above) as airborne_artifact_extractor.sh (or any other name with a .sh extension).
Make it Executable: Open your Terminal application, navigate to the directory where you saved the script, and run the following command:
chmod +x airborne_artifact_extractor.sh
Check macOS Quarantine Attribute (Important for downloaded scripts): If you downloaded this script from the internet, macOS might quarantine it, which can prevent it from running correctly or at all.
xattr airborne_artifact_extractor.sh
com.apple.quarantine, remove this attribute by running:
xattr -d com.apple.quarantine airborne_artifact_extractor.sh
If you still encounter issues running the script, especially if it's located in a directory like ~/Downloads, ensure that your Terminal application has necessary permissions (e.g., "Full Disk Access" in System Settings -> Privacy & Security) to access the script's location and the log archive.
^M errors (e.g., /bin/bash^M: bad interpreter: No such file or directory)If you encounter an error like bash: ./your_script_name.sh: /bin/bash^M: bad interpreter: No such file or directory, /usr/bin/env: ‘bash\r’: No such file or directory, or similar messages involving \r or ^M characters when trying to execute the script, it's likely due to Windows-style line endings (CRLF - Carriage Return Line Feed) instead of Unix-style line endings (LF - Line Feed).