Tag: Google’s Quick Share

Google Patches Quick Share Vulnerability Enabling Silent File Transfers Without Consent
News

Google Patches Quick Share Vulnerability Enabling Silent File Transfers Without Consent

Researchers studying cybersecurity have revealed a new flaw in Google's Quick Share data transfer tool for Windows that may be used to deliver arbitrary files to a target's device without their consent or cause a denial-of-service (DoS) attack. The vulnerability, known as CVE-2024-10668 (CVSS score: 5.9), circumvents two of the ten flaws that SafeBreach Labs first revealed in August 2024 under the QuickShell name. After responsible disclosure in August 2024, it has been fixed in Quick Share for Windows version 1.0.2002.2. Collectively known as CVE-2024-38271 (CVSS score: 5.9) and CVE-2024-38272 (CVSS score: 7.1), these ten vulnerabilities had the potential to be combined into an exploit chain that would have allowed for arbitrary code execution on Windows hosts. Similar to Apple ...
Researchers Uncover 10 Flaws in Google’s File Transfer Tool Quick Share
News

Researchers Uncover 10 Flaws in Google’s File Transfer Tool Quick Share

Up to ten security holes that might be combined to launch a remote code execution (RCE) chain on computers running the program have been found in Google's Quick Share data transfer app for Windows and Android. According to a technical report published with The Hacker News by SafeBreach Labs researchers Or Yair and Shmuel Cohen, the Quick Share application employs its own unique application-layer communication protocol to facilitate file transfers between adjacent, compatible devices. Through analyzing the protocol's inner workings, we were able to decipher and find manipulable or circumvented logic in the Windows Quick Share application read more about Researchers Uncover 10 Flaws in Google's File Transfer Tool Quick Share. Get up to date on the latest cybersecurity news and enha...