Affected Systems
Apple AirDrop and Google Quick Share wireless file transfer features on iOS, macOS, and Android devices. Specific affected versions not disclosed. Attack requires physical proximity (wireless range).
Exploitation Status
Vulnerabilities disclosed by researchers. No CVE assigned yet. Active exploitation status unknown. Proof-of-concept likely exists given researcher disclosure. Exploitation requires attacker within wireless range (Bluetooth/Wi-Fi Direct proximity).
Business Impact
Attackers in physical proximity can crash file sharing services causing denial of service, and bypass security controls without user interaction. High-density environments (offices, conferences, airports) face elevated risk. Service disruption impacts productivity. Security bypass could enable unauthorized file transfers or information disclosure. Severity mitigated by proximity requirement but concerning for targeted attacks.
Urgency
🟡 Within a week
Recommended Actions
- Disable AirDrop on iOS/macOS devices when not actively needed; set to 'Receiving Off' or 'Contacts Only' in settings
- Disable Google Quick Share on Android devices when not in use via Quick Settings or system settings
- Monitor vendor security advisories from Apple and Google for patches addressing these six flaws
- Implement network segmentation and physical security controls in sensitive areas to limit attacker proximity
- Educate users on risks of leaving wireless sharing features enabled in public or untrusted locations
