Researchers from the CISPA Helmholtz Center for Information Security discovered six security vulnerabilities in Apple's AirDrop and Samsung's Quick Share features. These wireless file-sharing services are used by over five billion devices worldwide, making the impact extensive.
The identified flaws allow attackers within wireless range to execute attacks that can crash file-sharing services on devices without requiring user interaction. The vulnerabilities stem from issues in session handling and trust decision processes in the protocols used by these technologies.
Apple has addressed one of the three AirDrop vulnerabilities, assigning it a CVE, though they haven't made public details readily available. Investigation and potential fixes for the remaining flaws are still ongoing. Google has paid a bounty for a flaw affecting its Quick Share application on Windows.
These vulnerabilities are significant due to their accessibility to attackers without needing prior connection or pairing, presenting substantial security risks. The research underscores the importance of scrutinizing proprietary protocol implementations for security flaws to safeguard billions of global users.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A study has identified six vulnerabilities in Apple's AirDrop and Android's Quick Share protocols, affecting over five billion devices. These security flaws, including pre-authentication issues and heap use-after-free vulnerabilities, present significant risks given their accessibility without prior pairing.
Researchers discovered six security flaws in Apple's AirDrop and Samsung's Quick Share, enabling attackers nearby to crash file-sharing services. Apple has already patched one of the identified vulnerabilities, but others remain under investigation, impacting potentially five billion devices globally.