PT-2024-27910 · Unknown · Quick Share

Published

2024-04-17

·

Updated

2025-04-07

·

CVE-2024-38271

CVSS v4.0

5.9

Medium

VectorAV:A/AC:H/AT:P/PR:L/UI:A/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions Quick Share versions prior to 1.0.1724.0
Description There exists an issue in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporary hotspot created for the sharing. As part of the sequence of packets in a Quick Share connection over Bluetooth, the attacker forces the victim to connect to the attacker’s WiFi network and then sends an OfflineFrame that crashes Quick Share. This makes the WiFi connection to the attacker’s network last, instead of returning to the old network when the Quick Share session completes, allowing the attacker to be a Man-in-the-Middle (MiTM).
Recommendations For versions prior to 1.0.1724.0, upgrade to version 1.0.1724.0 or above to resolve the issue. As a temporary workaround, consider disabling the Quick Share feature until a patch is available. Restrict access to unknown WiFi networks to minimize the risk of exploitation. Avoid using Quick Share over Bluetooth in public or untrusted environments until the issue is resolved.

Fix

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2025-05013
CVE-2024-38271

Affected Products

Quick Share