Skip to main content
Contributor I
May 6, 2025
Answered

Are Sonos products affected by the Airborne AirPlay exploit?

  • May 6, 2025
  • 21 replies
  • 692 views

As per the Oligo Airborne announcement, some high level exploits using AirPlay have been made public.  Tow of them - CVE-2025-24132 & CVE-2025-30422  affects Speakers and Receivers made with AirPlay SDK. Can someone from Sonos comment on whether Sonos products are susceptible to exploits, and if so, when they will be patched, and any products that may not be patched?

thanks,

Rob

This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.
Best answer by Corry P

Hi ​@gh208 

Thanks for bringing this particular thread back to my attention.

Yes, with yesterdays update, the Airplay vulnerability was patched on Sonos systems.

21 replies

Corry P
Sonos Staff
May 8, 2025

Hi ​@robzr 

Welcome to the Sonos Community!

Sonos takes customer security very seriously. We are aware of a recently disclosed vulnerability related to Apple AirPlay and are actively working to ensure our implementation includes the latest security updates from Apple. As a general best practice, we recommend ensuring your Sonos system is connected to a private, trusted WiFi network.

I hope this helps.

"Common sense is the collection of prejudices acquired by age eighteen." - Albert Einstein
Lyricist II
May 29, 2025

Hello Sonos,

Any updates on the Airborne issue? I’m staying in a hotel right now, and from my room I can see hundreds of AirPlay device, TVs and Sonos speakers included.

Would be good to know that people can’t use Sonos devices as a bridge into the network. I’m glad I travel with a pocket router, but even that is getting port scanned as I write this.

Please advise.

Corry P
Sonos Staff
May 29, 2025

Hi ​@gh208 

As I understand it, with a travel router in use you will be fine.

I hope this helps.

"Common sense is the collection of prejudices acquired by age eighteen." - Albert Einstein
Lyricist II
May 29, 2025

True, I am fine, while I am in my hotel room and behind my router.  Anyone who isn’t behind their own router might not be. I have a very small substack that I would love to inform that their Sonos is ok now. I know a lot of people that have turned off Airplay on their devices (like Roku) but this is not something that we can do on Sonos.

Corry P
Sonos Staff
May 29, 2025

Hi ​@gh208 

Anyone who isn’t behind their own router might not be.

Hence my earlier statement:

As a general best practice, we recommend ensuring your Sonos system is connected to a private, trusted WiFi network.

 

 

"Common sense is the collection of prejudices acquired by age eighteen." - Albert Einstein
Lyricist II
May 29, 2025

Hi Corry,

Can you please just provide a clear update?

Most people, including me, connect their Sonos speakers to a private, trusted Wi-Fi network. At least, it was trusted until we added a Sonos device. Until we know Sonos has patched the Airborne vulnerability that Apple addressed with the updated SDK, how can we treat the device as trusted?

So again, to repeat the original question that still hasn’t been answered:

Apple released an updated SDK about a month ago. Has Sonos implemented the fix for the Airborne vulnerability?

Appreciate a straight answer.

 

Corry P
Sonos Staff
May 29, 2025

Hi ​@gh208 

Apple released an updated SDK about a month ago. Has Sonos implemented the fix for the Airborne vulnerability?

No.

"Common sense is the collection of prejudices acquired by age eighteen." - Albert Einstein
Lyricist I
June 7, 2025

Hi ​@gh208 

Apple released an updated SDK about a month ago. Has Sonos implemented the fix for the Airborne vulnerability?

No.

Why does it take so long for Sonos to implement this fix? It is pretty ridiculous actually. We have Sonos speakers in our office, and because of security policy we had to turn them off. We basically bought expensive speakers that we are now unable to use for over a month! We are getting to the point that we’re thinking of throw them away, burn them and never look back to Sonos again! It is utterly disrespectful to have such complete lack of care about your customers security. 

Dear Sonos, Fix this ASAP!

106rallye
June 7, 2025

All I’ve read is that to exploit this vulnerability the attacker needs to be on your network. For consumers this is not a big problem. I would not know if implementing this fix is hard, so I cannot say if Sonos is taking a long time to implement this.

You are using consumer products in a work environment, which will bring up such consequences.

Lyricist II
June 10, 2025

Hello Corry P and Sonos!

My Sonos just applied an update.  Can you please confirm if this update includes the Airborne vulnerability fixes?

Thank you.