CVE Tools

AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks

The Hacker NewsBy The Hacker News

ResearchAirDropQuick Share

Our summary

Researchers reported six vulnerabilities across Apple AirDrop and Samsung Quick Share that let an attacker nearby disrupt the receiving service (crashing sharingd on macOS/iOS) without user interaction, potentially affecting multiple Continuity-related features at once. For Quick Share, Samsung’s Android issues can bypass session handshake checks, while Google’s Quick Share for Windows contains a memory safety problem consistent with a use-after-free, with a CVE still pending; the component has previously been linked to CVE-2024-38271, CVE-2024-38272, and CVE-2024-10668. The findings matter because these flaws require only local proximity or a shared network, meaning attackers in crowded locations could impact many nearby devices.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store