{"id":62007,"date":"2026-07-04T04:13:42","date_gmt":"2026-07-04T08:13:42","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=62007"},"modified":"2026-07-04T04:13:42","modified_gmt":"2026-07-04T08:13:42","slug":"airdrop-quick-share-flaws","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/airdrop-quick-share-flaws\/","title":{"rendered":"Six AirDrop and Quick Share flaws expose 5 billion devices"},"content":{"rendered":"<p>Security researchers have identified six critical vulnerabilities in Apple AirDrop and Google\/Samsung Quick Share, the default proximity file-sharing protocols used by over five billion devices worldwide. Conducted by Arash Ale Ebrahim and Nils Ole Tippenhauer of the <a href=\"https:\/\/www.cispa.de\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">CISPA Helmholtz Center for Information Security<\/a>, the first comprehensive reverse engineering and security analysis of these proprietary protocols reveals a broad attack surface ranging from denial-of-service (DoS) to authentication bypass and potential <a href=\"https:\/\/overcentral.com\/en\/splunk-critical-rce-bug\/\" title=\"Critical Splunk Enterprise Bug Allows Unauthenticated Remote Code Execution\" data-iacss-internal=\"1\">remote code execution<\/a> (RCE). The researchers developed a custom protocol-aware fuzzing framework called AIRFUZZ to uncover the flaws, which affect devices running macOS, iOS, iPadOS, Android, and Windows.<\/p>\n<h2>Five Billion Devices Exposed by Six Foundational Flaws<\/h2>\n<p>Apple AirDrop and Google Quick Share collectively serve more than five billion active devices, making them among the world&#8217;s most widely deployed proximity file-sharing technologies. AirDrop ships with macOS, iOS, and iPadOS, while Quick Share is Google&#8217;s standard nearby sharing platform across Android and Windows, with Samsung integrating it deeply into Galaxy smartphones. Because these services accept wireless connections from nearby devices without requiring prior pairing during initial discovery, they expose a significant pre-authentication attack surface. The researchers reconstructed AirDrop&#8217;s seven-layer protocol stack, including the previously undocumented DVZip adaptive compression format and more than 40 internal protocol commands, revealing that wireless file-sharing services have received far less academic scrutiny than their prevalence warrants.<\/p>\n<h3>Three Vulnerabilities in Apple AirDrop<\/h3>\n<p>The first AirDrop flaw is a pre-authentication DoS caused by a Swift <strong>fatalError()<\/strong> call in AirDrop&#8217;s HTTP path router. Sending a POST request to an unrecognized endpoint causes the privileged <strong>sharingd<\/strong> daemon to terminate immediately. Because the daemon also manages AirPlay, Handoff, Universal Clipboard, Continuity Camera, and other Continuity features, repeatedly triggering the crash can effectively disable multiple Apple services until the attack stops. The researchers confirmed the issue on macOS 15.7.3, macOS 26.3, iOS 18.x, and iOS 26.3.<\/p>\n<p>The second issue resides in Foundation&#8217;s XML property list parser, which performs recursive parsing without enforcing a nesting limit. A specially crafted XML property list containing hundreds of nested dictionary elements can exhaust the stack and crash applications that deserialize untrusted property lists. Because the vulnerable code exists within Foundation itself rather than in AirDrop alone, the flaw could affect applications across macOS, iOS, watchOS, tvOS, and visionOS that process attacker-controlled XML property lists.<\/p>\n<p>The third AirDrop <a href=\"https:\/\/overcentral.com\/en\/citrixbleed-vulnerability-exploited-24-hours\/\" title=\"CitrixBleed Vulnerability Exploited Within 24 Hours of Disclosure\" data-iacss-internal=\"1\">vulnerability<\/a> affects Apple&#8217;s Network.framework HTTP\/1.1 parser. Crafted requests with malformed transfer encoding or conflicting Content-Length headers can trigger a NULL pointer dereference, leading to another denial-of-service condition. The researchers note that the flaw could affect other Apple applications that use the same networking framework under similar conditions.<\/p>\n<h3>Quick Share Flaws on Android and Windows<\/h3>\n<p>On Samsung devices, the researchers found that application-layer protocol messages could be processed before the mandatory <strong>UKEY2<\/strong> authentication handshake completes, allowing unauthenticated interaction with portions of the protocol state machine. They also identified an encryption enforcement flaw in which three of seven post-handshake message types bypass mandatory SecureMessage protection and are processed in plaintext, enabling an on-path attacker to inject specific control messages into active sessions.<\/p>\n<p>The sixth vulnerability affects Google Quick Share for Windows. The researchers discovered a heap use-after-free condition in endpoint management that occurs during connection collision handling. Under specific race conditions involving simultaneous connection and disconnection events, the client dereferences a freed object, triggering a crash that the researchers believe could be exploited to enable remote code execution.<\/p>\n<h2>Vendor Patches and Current Status<\/h2>\n<p>Apple has acknowledged the three AirDrop vulnerabilities and stated that fixes are in progress. Samsung transferred its Quick Share reports to Google after determining the affected code originated from Google&#8217;s Nearby Connections components. Google acknowledged the Windows use-after-free vulnerability and rewarded the researchers through its Vulnerability Reward Program, while the Android Quick Share findings remain under investigation. The researchers have publicly released the AIRFUZZ framework, protocol documentation, and crash-reproduction scripts to aid further research.<\/p>\n<h2>What Users and IT Teams Should Do Now<\/h2>\n<p>Until official patches are fully deployed, users should consider disabling AirDrop and Quick Share when not actively transferring files in untrusted or public environments. Enterprise administrators should enforce endpoint detection and response (EDR) policies that monitor for unusual process behavior associated with proximity sharing services. For comprehensive endpoint protection against such wireless attack vectors, users should ensure their devices are running the latest operating system updates and deploy a reputable mobile device management (MDM) solution with advanced threat detection capabilities. Keeping all systems patched and maintaining strict network segmentation for sensitive devices remains the most effective immediate defense against these and similar wireless protocol vulnerabilities.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers have identified six critical vulnerabilities in Apple AirDrop and Google\/Samsung Quick Share, the default proximity file-sharing protocols used by over five billion devices worldwide. Conducted by Arash Ale Ebrahim and Nils Ole Tippenhauer of the CISPA Helmholtz Center for Information Security, the first comprehensive reverse engineering and security analysis of these proprietary protocols [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74306,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/CaYloQV.jpg","fifu_image_alt":"Six AirDrop and Quick Share flaws expose 5 billion devices","footnotes":""},"categories":[349],"tags":[],"class_list":["post-62007","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/CaYloQV.jpg","fifu_image_alt":"Six AirDrop and Quick Share flaws expose 5 billion devices","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=62007"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62007\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74306"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=62007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=62007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=62007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}