Skip to main content
  • Solde
  • Magasiner
  • Apprendre
  • Soutien
  • Professionnels
  • Panier

Security Advisory: 2025-0001

Advisory ID: SSA-2025-0001
Severity: High
Issue Date: 2025-06-10
CVE(s): CVE-2025-24132, CVE-2025-30422

Synopsis: Recent firmware updates address a security vulnerability in AirPlay implementation (CVE-2025-24132, CVE-2025-30422)

1. Impacted Products

  • All Sonos AirPlay-enabled devices.
  • Affected versions: All releases prior to Sonos Systems release v17.1 (build 85.0-65270) and Sonos S1 System release v11.15.3 (build 57.22-65130)

2. Introduction
Multiple vulnerabilities were identified in the AirPlay SDK implementation that affects third-party devices incorporating this technology, including Sonos's AirPlay-enabled products. This update remediates the vulnerability by implementing the patched AirPlay SDK with improved input validation and improved memory handling.

3. AirPlay Stack-Based Buffer Overflow Vulnerability (CVE-2025-24132)
Description: A stack-based buffer overflow vulnerability in the AirPlay implementation could allow an attacker on the local network to execute arbitrary code without user interaction
Known Attack Vectors: Malicious actors on the same local network could send specially crafted AirPlay requests to exploit this zero-click vulnerability
Resolution: To remediate CVE-2025-24132, apply the Sonos Systems release v17.1 (build 85.0-65270) and Sonos S1 System release v11.15.3 (build 57.22-65130) or later, which implements the patched AirPlay Audio SDK

4. AirPlay Authentication Bypass Vulnerability (CVE-2025-30422)
Description: A vulnerability in the authentication mechanism could allow an attacker to bypass authentication controls and gain unauthorized access to the device
Known Attack Vectors: Malicious actors on the same local network could send specially crafted authentication requests that bypass validation checks
Resolution: To remediate CVE-2025-30422, apply the Sonos Systems release v17.1 (build 85.0-65270) and Sonos S1 System release v11.15.3 (build 57.22-65130) or later, which implements the patched AirPlay Audio SDK
Additional Documentation: Apple Security Advisory: https://support.apple.com/en-us/122403
Acknowledgments: Sonos would like to thank the Oligo Security Research Team for their responsible disclosure of this vulnerability.


Trademark Attributions: Apple, AirPlay and other Apple marks are trademarks of Apple Inc., registered in the U.S. and other countries and regions. All third-party trademarks references in this document are property of their respective owners. Use of the does not imply affiliation with or endorsement by those entities.

Ne manquez jamais une note – ni une offre

Abonnez-vous pour recevoir en primeur les nouvelles sur les nouveaux produits et les offres exclusives.

Vous acceptez de recevoir des mises à jour, des offres promotionnelles et d'autres messages de Sonos. Vous pouvez vous désabonner à tout moment. Pour en savoir plus, consultez notre Déclaration de confidentialité.

Aide

  • Compte
  • Statut de la commande
  • Expédition et livraison
  • Retours
  • Localisateur de magasins
  • Nous joindre
  • Conditions de vente
  • Communauté Sonos

Aide

Offres

  • Dernière chance
  • Réusiné certifié
  • Programme de mise à niveau Sonos
  • Travailleurs de première ligne
  • Bêta de Sonos
  • Plan de Protection

Offres

À propos de Sonos

  • Notre société
  • Actualités
  • Trousses des médias
  • Carrières
  • Investisseurs
  • Durabilité et incidence
  • Nos débuts
  • Blogue
  • Application Sonos
  • Évaluations

À propos de Sonos

Pour les entreprises

  • Installed Solutions
  • Portail des développeurs
  • Métiers
  • Solutions commerciales
  • Boutique du revendeur
  • Compatible avec Sonos

Pour les entreprises

Catégories

  • Casques d’écoute
  • Haut-parleurs
  • Haut-parleurs portatifs
  • Cinéma maison
  • Barres de son
  • Ensembles
  • Architectural
  • Composantes audio
  • Accessoires

Catégories

Produits

  • Sonos Play
  • Sonos Ace
  • Arc Ultra
  • Beam (2e gén.)
  • Ray
  • Era 100
  • Era 100 SL
  • Era 300
  • Roam 2
  • Move 2
  • Sub 4
  • Sub Mini
  • Five
  • Amp
  • Port

Produits

© Sonos, Inc., 2026.
  • Juridique
  • Déclaration de confidentialité
  • Accessibilité
  • Conformité
  • Plan du site
  • Sécurité