Researchers from the Helmholtz Center for Information Security (CISPA) have reported six potential vulnerabilities in popular wireless data sharing services. Three of these affect Apple's AirDrop, while the other three impact Quick Share, the communication system between Android devices and Windows PCs. According to experts, the issue is systemic because both services operate in the background and continuously scan the surrounding area to detect nearby gadgets.

Six Vulnerabilities Across Two Ecosystems

The key feature of AirDrop and Quick Share, according to researchers, is that they do not require prior confirmation from the device owner to read and process data. This means the services are essentially "listening" to the airwaves continuously, even when the user has not initiated a file transfer. It is precisely this architecture that creates an attack surface: an attacker can interact with the background process without obtaining the victim's consent.

Attack Mechanics: Background Scanning and 30 Meters

To execute an attack, according to CISPA data, an attacker only needs a laptop with a Wi-Fi module and to be within 10 to 30 meters of the target, provided the discovery setting is set to "Everyone." On Apple devices, failures occur due to a defect in the background process sharingd, which is responsible not only for AirDrop but also for Continuity Camera, Handoff, and other ecosystem functions. By sending specially crafted commands, an attacker can completely crash this process and trigger an emergency shutdown of the services.

Bypassing Checks in Quick Share and Windows

In the case of Quick Share and Windows, the situation is more complex, according to researchers, due to the possibility of bypassing built-in security checks. It is important to emphasize: the discovered vulnerabilities, as noted by CISPA, do not allow attackers to steal users' personal data. Their effect is the disruption of stable device operation and the failure of sharing services, rather than data leakage. Nevertheless, for corporate and public scenarios where file sharing is critical, such a failure can have practical consequences.

Contradictory Data

In the researchers' initial description and materials from specialized publications (securitylab.ru), there is mention of six vulnerabilities and the fact that patches have been released for only two of them, while work continues on the remaining four. However, a number of publications (specifically rbc.ua) operate with the figure "5 million iPhones and Androids under hacker fire" in their headlines. Specific justification for this assessment is absent in the provided sources, so it should be viewed as an editorial extrapolation rather than a fact confirmed by vendors or researchers. Differences in the presentation of the number of affected devices and the status of patches constitute the area of discrepancy that the editorial team highlights separately.

What Users Should Do: Visibility Settings

Until official updates are released for all four remaining vulnerabilities, experts advise users to manually reduce the attack surface. The practical recommendation is to change the visibility settings for AirDrop and Quick Share, disabling the "Everyone" mode and switching to "Contacts Only" or a similar limited option. This reduces the set of devices the service is ready to accept over the air and lowers the probability that the background process will process malicious commands from an external source.

Patch Status and Vendor Response

CISPA researchers have already sent reports of the found issues to Apple and Google. At the time of publication, according to available data, developers have released security patches for two of the six vulnerabilities, while work on official updates continues for the remaining four. Users of both ecosystems are advised to monitor their device support channels and install updates as they become available, without delaying them.