HomeSecurityAirDrop & Quick Share: 6 vulnerabilities allow crashes and bypasses

AirDrop & Quick Share: 6 vulnerabilities allow crashes and bypasses

Six serious security vulnerabilities have been discovered in Apple ’s AirDrop and Google and Samsung ’s Quick Share , allowing near-miss attackers to cause service crashes and bypass critical security checks. The AirDrop vulnerabilities affect macOS and iOS devices , while the Quick Share flaws affect both Android and Windows . According to The Hacker News, the total ecosystem exposed numbers over five billion active devices .

AirDrop & Quick Share: 6 vulnerabilities

The research, conducted by Arash Ale Ebrahim and Nils Ole Tippenhauer of the CISPA Helmholtz Center for Information Security , is the first systematic analysis of both protocols simultaneously, focusing on the application layer. The finding is particularly important because the attack does not require prior connection or pairing with the targeted device — all it requires is a laptop within wireless range.

See also: Quick Share: Expanding AirDrop support to more Android phones

The finding comes at a time when Quick Share is gaining more importance: Google and Samsung have expanded its interoperability with Apple 's AirDrop , increasing the value of the feature for both consumers and businesses. At the same time, Google announced more than 120 fixes for Android vulnerabilities this month , including an actively exploited zero-day , which highlights that the attack surface on mobile platforms remains a high priority.

AirDrop Vulnerabilities: How the Apple Ecosystem is Collapsed

All three AirDrop vulnerabilities have the same result: crashing the sharingd service , which runs in the background on macOS and iOS . This service handles not only AirDrop , but also AirPlay , Handoff , Universal Clipboard , Continuity Camera , and NameDrop — so a single crash renders the entire feature set useless. The simplest of the three vulnerabilities requires only a maliciously crafted request sent to a device with AirDrop set to receive from “Everyone.” By sending these messages every two seconds, the features remain disabled. In the researchers’ testing, no legitimate AirDrop transfers occurred during the attack.

AirDrop & Quick Share: 6 vulnerabilities allow crashes and bypasses

As for the other two bugs, they don't just affect AirDrop but also Apple's shared frameworks. The most extensive is a stack overflow in Foundation's XML property list parser, triggered by a small file with about 200 nested levels.

Any Apple app that opens an untrusted file of this type could encounter the same parser path, across macOS, iOS, watchOS, tvOS, and visionOS. The researchers reproduced the AirDrop bugs on macOS 15.7.4, macOS 26.3, iOS 18.x, and iOS 26.3. An earlier version of iOS 16 was not affected.

Quick Share: Samsung and Google vulnerabilities that undermine security

On Android , two vulnerabilities in Samsung ’s Quick Share allow an attacker to bypass the handshake that is supposed to secure a session. One vulnerability allows an unauthenticated device to initiate a connection before UKEY2 encryption is complete , while the other allows certain control messages to pass through unencrypted even after a secure session is established. An attacker on the same Wi-Fi network could exploit this gap to force a connection to an “accepted” state, maintain it, or cause the server to return IP and port values ​​that they control. The tests were conducted on a Galaxy S23 Ultra running Android 16 and Quick Share v13.8.01.11 .

See also: Samsung Quick Share: AirDrop support on Galaxy S26

The most serious vulnerability was found in Google Quick Share for Windows (version v1.0.2472.1 ). It is a use-after-free memory error that occurs when two connections collide at the right time, forcing the program to use a memory segment that has already been freed. This type of error can potentially be exploited for code execution, and the researchers point out that this scenario is likely, since Windows Control Flow Guard defenses are disabled in the application. Google has acknowledged the issue, paid a bug bounty and implemented a fix, while the corresponding CVE is still pending.

As for fixes, Apple has already patched one of the three AirDrop and it has been assigned a CVE, although the related announcement is not yet public; the other two are in the process of coordinated disclosure. The two Samsung have been handed over to Google and remain under investigation. There have been no public reports of exploitation of these vulnerabilities so far.

AirDrop & Quick Share: 6 vulnerabilities allow crashes and bypasses

Practical recommendations for protecting against AirDrop and Quick Share vulnerabilities

To protect against these vulnerabilities, researchers and security experts recommend setting AirDrop to “Contacts Only” or the most restrictive visibility option — especially in public places. Similarly, Quick Share should be disabled or limited to trusted contacts, especially on managed devices used in offices or conferences. Immediate application of security updates to iOS, macOS, Android , and Windows is imperative, given that the vulnerabilities span multiple platforms.

See also: Google fixes vulnerability in Quick Share that causes DoS

For organizations, it is recommended that they implement Mobile Device Management (MDM) that restrict device discovery, require current security updates, and provide user education about file transfers. In high-risk environments, disabling proximity sharing features and using managed alternatives — such as corporate file portals or encrypted collaboration tools — is the most secure option. This research is a reminder that wireless file transfer features are not just convenience tools — they are part of the attack surface that should be systematically assessed.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS