Six Bugs in AirDrop and Quick Share Let Anyone Within Range Knock Out File Sharing

Researchers chained wireless-range flaws to crash receiving devices and bypass Quick Share permission checks, no taps, no pairing, no prompts.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Six Bugs in AirDrop and Quick Share Let Anyone Within Range Knock Out File Sharing
Share

Key points

  • Two researchers found six vulnerabilities in AirDrop and Google's Quick Share, the proximity file-transfer stacks built into iOS, macOS, Android and Windows.
  • An attacker within Bluetooth or Wi-Fi range can crash the AirDrop service on a Mac or iPhone set to receive from anyone, with no user interaction.
  • Quick Share flaws bypass the permission checks Google added after the 2024 patch round that closed a remote-code-execution chain disclosed at DEF CON.
  • CVE assignments, patched versions and a technical writeup have not yet been published.
  • Setting AirDrop to "Contacts Only" or off, and Quick Share to "Your devices" or off, is the practical mitigation today.

What did the researchers actually find?

Six security flaws across two proximity file-transfer stacks: AirDrop on Apple devices and Quick Share on Android and Windows. The headline result is a zero-click denial of service. A nearby attacker, carrying only a laptop and no prior connection to the target, can crash the sharing daemon on a Mac or iPhone configured to receive from "Everyone." The target sees nothing, taps nothing, the service just stops.

On the Quick Share side, the bugs target handshake and capability-negotiation logic, the code that decides whether a sender may push a file without explicit approval. Those checks were the same layer Google hardened after the 2024 Quick Share patch round, which itself closed a remote-code-execution chain shown at DEF CON. The new findings suggest that hardening was incomplete.

We first covered Quick Share security in our 19 June briefing on Apple's Beats Bluetooth patch and related wireless fixes, where proximity-stack exposure was already emerging as a theme worth tracking.

Should you worry about your location?

The attack surface is whoever you're sitting next to. Airports, transit hubs, conference floors, coworking spaces. "Receive from Everyone" is the highest-risk setting on Apple devices; "Contacts Only" narrows exposure, though not to zero across all six issues. On Android and Windows, Quick Share's visibility setting plays the same role.

This is a wireless-range bug class, not a network one. VPNs and firewalls don't help. The attack travels over the AWDL, Wi-Fi Direct or BLE negotiation layer that sits well below anything a perimeter sees.

Are crashes the worst case?

For now, crashes are the confirmed floor. A reliable remote crash in a privileged, always-listening daemon is frequently a stepping stone to memory-corruption research. Neither researcher has claimed remote code execution from these six issues specifically, but the pattern, a parser fault in a service exposed to unauthenticated peers, is exactly the pattern that produced earlier AirDrop and Quick Share RCEs. Watch for a full technical writeup; I'll link it here when it drops.

What should you patch or change today?

CVE numbers, CVSS scores and patched-version strings were not included in the initial disclosure. I'll update once Apple posts to its security releases page and Google publishes advisory details. Quick Share for Windows updates ship through the standalone installer, so enterprise patch teams should not assume MDM coverage picks them up automatically.

Mitigation until patches arrive is unglamorous but effective: set AirDrop to "Receiving Off" or "Contacts Only" when you're not mid-transfer, and set Quick Share visibility to "Your devices" or off. Toggle on, transfer, toggle off. That's the habit worth building.

The practical judgement here: crashes in proximity daemons rarely stay crashes for long, and the fact that these bugs survive a patching round that was explicitly meant to close this attack surface suggests the handshake logic deserves a harder look than Google gave it.

© 2026 Threat Vectr