Research AirDrop ics-ot-iot Quick Share Apple web-app
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
CVE Tools coverage
Researchers reported six vulnerabilities across Apple AirDrop and Samsung Quick Share that let an attacker nearby disrupt the receiving service (crashing sharingd on macOS/iOS) without user interaction, potentially affecting multiple Continuity-related features at once. For Quick Share, Samsung’s Android issues can bypass session handshake checks, while Google’s Quick Share for Windows contains a memory safety problem consistent with a use-after-free, with a CVE still pending; the component has previously been linked to CVE-2024-38271, CVE-2024-38272, and CVE-2024-10668. The findings matter because these flaws require only local proximity or a shared network, meaning attackers in crowded locations could impact many nearby devices.