Researchers from the CISPA Helmholtz Center for Information Security have revealed new security flaws in Apple's AirDrop and Google's Quick Share systems. These vulnerabilities affect more than five billion active devices worldwide. An attacker only needs to get within 30 meters with a laptop and can exploit the weaknesses without any physical contact, phishing link, or Wi-Fi access.
How the flaws work
Both file sharing systems run highly privileged services in the background that activate as soon as another device appears nearby. This approach prioritizes convenience over security. With AirDrop, the issue lies in a background daemon that controls not only AirDrop but also AirPlay, Handoff, Universal Clipboard, and Continuity Camera. A single malformed request can crash the entire system. If the attacker repeats this request every few seconds, they can hold the Apple ecosystem essentially hostage and permanently disable these functions.
Quick Share on the Android side is no better. Researchers tested a Samsung Galaxy S23 Ultra and Google's Windows client. They discovered logical bypasses that allow attackers to completely circumvent critical authentication steps. Additionally, they found a memory handling bug in the Windows version. Even though Apple and Google share virtually no code, both fell into the same trap: sacrificing security for convenience and exposing complex background processes before verifying the sender's identity.
Implications for regular users
Fortunately, this is not about data theft – attackers cannot simply steal private photos. For most users, these flaws represent a major nuisance in the form of a denial of service (DoS). However, if you frequently transfer files using AirDrop or Quick Share, it can be very frustrating when someone hijacks your connection state.
Available fixes and recommendations
Apple has already fixed one of the three AirDrop flaws in a recent update. Google has also released a fix for its Windows client. The remaining issues, including the bypasses on Samsung, are still under development or in coordinated disclosure. But don't just wait for software updates. The most vulnerable users are those who have their devices set to receive files from 'everyone'. Immediately go to Settings > General on iPhone or the Quick Share menu on Android and change visibility to 'Contacts Only' – or turn off reception entirely.