top of page

Warning: Over 5 billion iPhone and Android devices face risk of covert attacks

Transferring images, videos, or documents between phones and computers has now become incredibly simple thanks to AirDrop on Apple devices or Quick Share on Android and Windows operating systems. Users no longer need to connect to the same Wi-Fi network, perform complex pairing, or log into any account. However, this very convenience is inadvertently opening a loophole for cyberattacks, threatening the safety of more than 5 billion devices worldwide.

Billions of devices face risks from the "friendliness" of technology

A recent study by cybersecurity experts at the CISPA Helmholtz Center for Information Security (Germany) has pointed out a worrying reality. The seamless experience we enjoy daily is actually powered by background services running on the devices.

These services actively scan and communicate with any device that enters their coverage range without waiting for user permission. The absolute and automated trust between systems inadvertently becomes a fatal flaw, allowing security vulnerabilities to be deeply exploited.


The nature of the 6 vulnerabilities on popular platforms

Researchers have discovered a total of 6 dangerous security vulnerabilities, equally divided among currently popular platforms including iOS, Android, macOS, and Windows.

For devices within the Apple ecosystem, 3 vulnerabilities were found in a background process called sharingd. This is the core component responsible for operating not only AirDrop but also a host of other interconnected features such as AirPlay, Universal Clipboard, Continuity Camera, and Handoff.

Meanwhile, the remaining 3 vulnerabilities are directly related to Quick Share and the connection system between Android phones and Windows computers. The mechanism of Quick Share allows devices to exchange and respond to the first 3 data frames before the security code authentication process takes place; notably, this data is completely unencrypted. Even if the user cancels the connection session, the security key for that session is retained, allowing bad actors to reopen the link for deeper exploitation. On the Windows operating system, this flaw also creates a "use-after-free" phenomenon—a type of memory allocation error that can cause the system to behave unexpectedly.

How can bad actors attack you?

What is concerning is that the hackers' approach method is quite simple. If users set the visibility mode of AirDrop or Quick Share to "Everyone", an attacker only needs to be equipped with a laptop capable of Wi-Fi connectivity.

By standing within a range of 3-4 meters up to about 10-30 meters around the target, bad actors can send malicious commands directly to the device's background service. With AirDrop, this attack will completely paralyze the sharingd process, causing the application to crash and leading to the disruption of related features such as Continuity Camera or Universal Clipboard.

Immediate measures for self-data protection

On a positive note, all of these security flaws have been reported to Apple and Google. Currently, two out of the six vulnerabilities have been patched by the companies, while the remaining four are undergoing further investigation to release an official update in the near future.

Although current attacks are reported to be unable to directly steal data from users' devices, proactive prevention remains essential. Experts recommend that users proactively change the sharing range settings on their devices.

Instead of leaving it on "Everyone", you should switch the configuration to "Contacts Only" or turn it off completely using the "Nobody" mode. Only when there is an actual need to transmit or receive data should you turn this feature on. This may slightly reduce convenience when sharing multiple files, but in return, your device will be safely protected against unknown connections from strangers around you.

Experts recommend that users proactively change the sharing range settings on their devices.
Experts recommend that users proactively change the sharing range settings on their devices.
This security incident serves as a reminder that the more convenient features are, the higher the level of caution required from users. In the context of increasingly sophisticated forms of cyberattacks, understanding the operational mechanisms and changing small setting habits on phones and computers will help us minimize the risk of becoming targets for tech criminals in the future.

References: baonghean.vn, bgr.com 

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page