HeadlinesBriefing favicon HeadlinesBriefing.com

Apple AirDrop Vulnerabilities Expose iPhone and Mac to Remote Crashes

9to5Mac •
×

Security researchers have identified three AirDrop vulnerabilities affecting both iPhone and Mac devices, with similar flaws discovered in Android's Quick Share. These security issues can cause AirDrop, AirPlay, Handoff, Universal Clipboard, and Continuity Camera to crash and remain unavailable during an active attack.

The exploit requires only a laptop with Wi-Fi and proximity within 10 to 30 meters, making it remarkably simple to execute. No pairing, contact exchange, or shared network connection is needed. On Apple devices configured to receive from 'Everyone,' the protocol responds before user prompts appear, allowing attackers to trigger crashes through malformed web requests that hit unrecognized paths in the code.

Researcher Arash Ebrahim noted that such vulnerabilities reflect common engineering challenges in proximity-based protocols across platforms. Apple has fixed one of the three vulnerabilities and assigned it a CVE identifier, while the remaining two issues are still under coordinated disclosure. The company has not yet published the corresponding security advisory.

While no data theft occurs, this vulnerability demonstrates how seamless cross-device experiences can create large pre-authentication attack surfaces. Users should consider adjusting AirDrop settings to limit exposure until patches are complete.