securityonline.info 8/13/2026, 4:11:14 PM · external

Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public

Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public
CyberSIXT Evidence Panel
Primary Source blog.byterialab.com

A researcher discovered a zero-click vulnerability in Xiaomi's ShareMe file-sharing app, allowing attackers within Bluetooth LE range to send arbitrary files to a victim's phone without any user consent or notification. This flaw affects over 1 billion devices and poses significant risks, as files can be sent immediately upon entering Receive mode. Key issues include exposure of WiFi credentials, lack of proper authentication, and the ability for attackers to suppress notifications.

A public proof-of-concept exploit is available, but there are currently no reported cases of this vulnerability being exploited in the wild. Users are advised to keep their app updated and to avoid using Receive mode in crowded areas until a fix is provided.

View Primary Source Via securityonline.info

Article by CyberSIXT