PatchSiren

AirVPN CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH AirVPN CVE published 2026-01-06

CVE-2025-14979

AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root. This issue affects Eddie: 2.24.6. The vulnerability is a high-severity issue that can allow attackers to gain elevated privileges, potentially leading to lateral movement and exploitation within the local network. System administrators and security teams should assess exposure [truncated]