CVE-2024-38272 HIGH

CVE-2024-38272: Auth Bypass in Quick Share

Vendor Google
Product Nearby
Weakness CWE-294
Published June 26, 2024
Last update August 2, 2024

CVSS base score

7.1/10
Attack vector Adjacent
Attack complexity High
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L

What the vulnerability does

01Description

There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows. Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or contacts mode. We recommend upgrading to version 1.0.1724.0 of Quick Share or above

Key dates

02Disclosure timeline

June 26, 2024 CVE published
August 2, 2024 Record updated