CVE-2024-38271 describes a vulnerability in Google Quick Share/Nearby that allows an attacker to force a victim to remain connected to a malicious Wi-Fi hotspot after a Quick Share session, enabling a Man-in-the-Middle (MiTM) attack. The vulnerability has a CVSS score of 4.8 (Medium), indicating an adjacent attack vector, high attack complexity, and requiring user interaction, with a potential impact of high availability loss. While not currently listed on the KEV catalog or having public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, suggesting awareness among researchers. Users are advised to upgrade to Quick Share version 1.0.1724.0 or above to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.1724.0CPE matchmatch criteria | cpe:2.3:a:google:nearby:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:A/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.