Apple AirDrop and Android Quick Share are the kind of phone features you probably use without thinking much about them. You want to send a photo across the room. You want to move a file from your phone to your laptop. So you tap share, pick a nearby device and move on.
Now, new security research shows those handy nearby-sharing tools can also create a wireless opening around your phone.
Researchers at the CISPA Helmholtz Center for Information Security examined Apple AirDrop and Android Quick Share. They found six vulnerabilities across Apple, Samsung and Google implementations. The flaws include AirDrop crash bugs, Samsung Quick Share protocol issues and a Google Quick Share for Windows bug that could potentially lead to remote code execution.
BEFORE YOU CONNECT ANOTHER SMART TV, TABLET OR PHONE, LOCK IT DOWN
That can affect you in a very everyday way. Your phone may be sitting in your pocket at an airport gate, in a coffee shop or inside a packed conference room while it listens for nearby sharing requests. If a bad actor gets close enough, they could try to take advantage of that open wireless doorway before you even realize anything happened. So, before you leave AirDrop or Quick Share open again, here is what the research found and the settings worth checking now.
Free live CyberGuy class: Sick of Spam? Join us July 22.
Join us Wednesday, July 22, at 1 p.m. ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt “CyberGuy” Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. Youll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.
Reserve your free spot today at CyberGuyLive.com.
The researchers call this a proximity problem. AirDrop and Quick Share are built to find nearby devices without the usual setup of pairing first. That convenience is the whole point. It also means the sharing software has to listen before it fully trusts the other device.
According to the research, the affected protocols are used by more than five billion devices. Apple reports more than 2.2 billion active devices running the sharing service tied to AirDrop. Google reports more than 3 billion Android devices with Quick Share available system-wide or used as a default sharing tool on many phones.
The study found three AirDrop issues that could be triggered before authentication. It also found two Samsung Quick Share protocol flaws. In addition, researchers found one Google Quick Share for Windows use-after-free bug. Apple, Samsung and Google acknowledged the reports, according to the researchers.
Most phone attacks we talk about involve bad links, fake login pages or shady apps. This research points to a different kind of risk because it starts with physical proximity. A nearby attacker may not need your password. They may not need you to open a website either. In some cases, the target device only needs to be discoverable or in a sharing mode that listens for nearby devices.
That does not mean someone can grab every photo on your phone by standing next to you. The known flaws are narrower than that. Still, the research shows that file-sharing features sit closer to sensitive parts of the system th