ADVERTISEMENT

Apple’s AirDrop and Android’s Quick Share vulnerable: nearby hackers initiate connection, crash devices, or worse

Five billion iPhones and Android phones are listening for potential file drops via AirDrop and Quick Share, leaving users exposed to nearby hackers who can cause crashes, tamper with active transfers, or, potentially, even run code. Researchers have probed the protocols and disclosed six security flaws.

Apple AirDrop and Android Quick Share have security flaws

Image by Cybernews.

Ernestas Naprys
Ernestas Naprys Senior Journalist
June 30, 2026 Updated: July 1, 2026 3 min read
Key takeaways:
Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.

Check if your data has been leaked

Find out if your email, phone number or related personal information might have fallen into the wrong hands.
18,611,353,922
Breached accounts
36,030
Breached websites

Bombarding the software with malformed inputs

ADVERTISEMENT
Samsung to Apple airdrop
Image by Cybernews
  • The device processed certain commands before authentication was complete, allowing an attacker to initiate a Quick Share connection and manipulate the connection process, keeping unwanted sessions alive.
  • An on-path attacker on the same WiFi network can inject unencrypted control frames into an active Quick Share transfer, defeating the device-to-device encryption layer.
  • Google Quick Share for Windows contains a use-after-free bug, which can be triggered by a race condition. Researchers assessed that it could be developed into a full remote code-execution exploit, and they were awarded a bug bounty.

ADVERTISEMENT