Tag: Quick Share Vulnerability

Google Patches Quick Share Vulnerability Enabling Silent File Transfers Without Consent
News

Google Patches Quick Share Vulnerability Enabling Silent File Transfers Without Consent

Researchers studying cybersecurity have revealed a new flaw in Google's Quick Share data transfer tool for Windows that may be used to deliver arbitrary files to a target's device without their consent or cause a denial-of-service (DoS) attack. The vulnerability, known as CVE-2024-10668 (CVSS score: 5.9), circumvents two of the ten flaws that SafeBreach Labs first revealed in August 2024 under the QuickShell name. After responsible disclosure in August 2024, it has been fixed in Quick Share for Windows version 1.0.2002.2. Collectively known as CVE-2024-38271 (CVSS score: 5.9) and CVE-2024-38272 (CVSS score: 7.1), these ten vulnerabilities had the potential to be combined into an exploit chain that would have allowed for arbitrary code execution on Windows hosts. Similar to Apple ...