Public Report: Android Quick Share Application Penetration Test
NetSPI conducted a penetration test of Android Quick Share to assess the security of its new cross-platform sharing compatibility. NetSPI reviewed the implementation for vulnerabilities and data leakage both in transit and in on-device storage. NetSPI performed testing of the file transfer, session validation, previous related vulnerabilities, data storage, and other attack vectors. The penetration test discovered just one low-severity issue, which was remediated prior to launch. With this remediation, the engagement found that Quick Share’s new cross-platform sharing capability does not introduce any new security or privacy risks to Android or iOS users.
A full report is available for viewing here.
Explore More Blog Posts
Stealing the Artifact – JFrog Artifactory Vulnerability
Discover how NetSPI uncovered and reported vulnerabilities in JFrog Artifactory that allowed unauthenticated attackers to bypass authentication and steal an arbitrary artifact.
Azure VM Command Execution using Third-Party Extensions – Salt Minion
In part two of our series, learn how attackers can leverage this legitimate tool to achieve undetected, arbitrary code execution as root, and explore the key detection methods you need to protect your Linux and Windows environments.
Azure VM Command Execution using Third-Party Extensions – Chef
Discover how a privileged principal in Azure can abuse third-party extensions like Chef to achieve arbitrary command execution on target VMs by deploying malicious cookbooks to extract Managed Identity tokens.