Back Heise.De Security vulnerabilities discovered in Apple's AirDrop and Android's Quick Share
Security researchers from the CISPA Helmholtz Center for Information Security have discovered three vulnerabilities in Apple's AirDrop function for wireless data transfer. Fortunately, none of the vulnerabilities can be exploited to execute malicious code. However, it is bad enough that they can be used to trigger crashes. Another three security vulnerabilities have been uncovered in Google's and Samsung's Quick .
Arash Ale Ebrahim and Nils Ole Tippenhauer developed the test program “AirFuzz” specifically for their research, a tool that automatically sends faulty or manipulated data packets to AirDrop to provoke crashes and malfunctions. The focus was on the application layer of the functions, not on vulnerabilities at the pure radio level.
Two of the three AirDrop vulnerabilities can already be triggered when AirDrop is set to “Everyone.” The third is only reached after accepting a transfer.
A single, incorrectly formatted HTTP request is sufficient to crash the responsible system service sharingd . This not only brings AirDrop to a standstill but also related functions such as AirPlay, Handoff, and clipboard synchronization between devices.
A second vulnerability lies in the processing of property lists, an internal data format, and can cause a buffer overflow through nested data structures. A third vulnerability in Apple's network framework can be provoked by prepared HTTP headers.
The researchers explicitly emphasize that ten different attempts to bypass the actual user confirmation for file transfers all failed – Apple's check of the Apple ID therefore holds up.
With Quick , the researchers found two problems in Samsung's implementation: Firstly, the service processes certain data packets before the actual authentication handshake is completed. Secondly, three out of seven message types are also processed if they arrive unencrypted, contrary to the specification – an attacker in the same WLAN could thus manipulate connections or artificially keep sessions alive.
Most serious is a finding in Google's Quick client for Windows: a so-called use-after-free error, where the program accesses already freed memory. This class of errors can be misused for code execution under certain circumstances. While the researchers were able to trigger a reliable crash, they could not develop a complete exploit.
Apple has confirmed the three AirDrop vulnerabilities, and fixes are reportedly being worked on by the researchers. Samsung has forwarded its two findings to Google, as the affected code originates from Google's Quick components; these are currently still being reviewed. Google has confirmed the Windows vulnerability and rewarded it with a bug bounty.
The attacks only work within a relative radio proximity of 10 to 30 meters; an attacker must therefore be physically close to the target device. However, in densely populated environments such as airports, train stations, or conferences, theoretically many devices could be targeted simultaneously.
Since no patches are available yet, caution is advised for now: If you do not actively use AirDrop, you should avoid the mode that makes you visible to everyone in the vicinity for a few minutes, or at least keep it as short as possible. Similar caution applies to Quick in unknown environments with visibility enabled for all devices.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
