Security researchers have identified three distinct vulnerabilities in Apple’s AirDrop file-sharing protocol, with Apple reportedly working on a comprehensive fix that may take multiple update cycles to fully resolve.
Three Weak Links in Apple’s Local Sharing Chain
According to 9to5Mac, the three vulnerabilities affect the AirDrop implementation across iOS and macOS. The flaws are understood to potentially allow attackers to leak identifying information about nearby AirDrop users, even when the feature is set to Contacts Only mode.
A Patch in Progress, But Not Without Delays
Apple has acknowledged the issues and is working on a full fix. The company has implemented partial mitigations in recent iOS and macOS updates, but researchers say the complete fix requires more fundamental changes to the AirDrop architecture.
Turning Off AirDrop Until the Fix Lands
While Apple develops a permanent fix, users concerned about AirDrop privacy can disable the feature entirely or set it to receive from Contacts Only. The most secure option is to disable AirDrop when not actively using it.