Apple AirDrop, Android Quick Share flaws put phones at risk
A research team at the CISPA Helmholtz Center examined wireless file-sharing functionality built into modern smartphones and discovered multiple security defects affecting implementations from Apple, Samsung, and Google. The vulnerabilities span different severity levels—some cause devices to crash when receiving malformed requests, whilst others expose protocol weaknesses in Samsung's system and a particularly serious flaw in Google's Windows version that could enable attackers to execute commands remotely on affected machines.
The practical danger lies in the always-listening nature of these features. When users have file-sharing enabled, their devices remain open to nearby connections in public environments such as airports, cafés, and conference halls. An attacker positioned close enough could attempt to exploit these wireless entry points before the device owner realises an intrusion attempt has occurred, potentially compromising the phone without any visible warning.
- Security researchers identified six vulnerabilities in Apple AirDrop and Android Quick Share across implementations by Apple, Samsung, and Google
- Flaws range from crash bugs to protocol weaknesses and potential remote code execution, exploitable when attackers get physically close to listening devices in public spaces