[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJB0Yf4bXSLCmj0fIwvjoe1FDdUcE4FguJPsdiNKRVVY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"0af4a693-6919-4f88-95e7-9b8cb2a9d85c","airdrop-quick-share-flaws-expose-billions-to-nearby-attacks","1a4ee62d-abd5-495b-a874-09b2d7feda86","AirDrop & Quick Share Flaws Expose Billions to Nearby Attacks","Researchers discovered six vulnerabilities in Apple AirDrop and Google Quick Share that allow physically nearby attackers to crash sharing services or bypass security controls without user interaction. The flaws affect billions of devices running macOS, iOS, Android, and Windows, highlighting how commonly trusted peer-to-peer sharing features can become attack surfaces. Apple has patched only one of the reported flaws, while Google addressed a memory corruption bug in its Windows app, leaving partial exposure. The incident underscores the danger of delayed or incomplete patch cycles for widely deployed, proximity-based communication features that users typically leave enabled by default.","**Immediate actions:**\n- Apply all available patches from Apple and Google immediately, ensuring AirDrop and Quick Share are updated to their latest versions.\n- Disable AirDrop and Quick Share on devices where the feature is not actively needed, reducing the attack surface until full patches are available.\n- Restrict AirDrop discovery settings to 'Contacts Only' rather than 'Everyone' to limit exposure to unknown nearby devices.\n\n**Long-term improvements:**\n- Establish a structured patch management process that tracks vendor advisories for built-in OS features, not just third-party software.\n- Maintain an up-to-date inventory of all endpoints and their enabled wireless sharing capabilities (AirDrop, Quick Share, Bluetooth, NFC).\n- Conduct periodic threat modeling exercises for proximity-based and peer-to-peer features embedded in operating systems.\n\n**Detection measures:**\n- Monitor endpoint security logs for anomalous crash events or unexpected service restarts associated with AirDrop or sharing daemons.\n- Deploy mobile device management (MDM) policies to enforce and audit the state of wireless sharing features across the device fleet.\n- Subscribe to vendor security advisories (Apple Security Updates, Google Android\u002FChrome OS bulletins) to receive timely notification of future patches.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 12: Network Infrastructure Management","NIST SP 800-40: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST CM-7: Least Functionality (Restrict Unnecessary Features)","NIST RA-5: Vulnerability Monitoring and Scanning","ISO\u002FIEC 27001 A.12.6.1: Management of Technical Vulnerabilities","ITIL Change Management: Emergency Change Procedures","published","2026-06-30T12:22:06.160021+00:00","2026-06-30T12:22:05.845+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002Fairdrop-and-quick-share-flaws-let.html","airdrop-and-quick-share-flaws-let-nearby-attackers-trigger-crashes-and-bypass-ch-a8bf71","AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]