Airvpn is a VPN service provider with a narrowly scoped product portfolio centered on its Eddie client application. The observed vulnerability signal focuses on improper permission assignment for critical resources, a weakness class characteristic of access-control implementation in client software handling sensitive network and credential data. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Airvpn over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14979HIGH AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6. | Jan 6, 2026 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Airvpn.
Media articles that mention a CVE ID that affects a product developed by Airvpn — matched by CVE ID, not by vendor name.