ES File Explorer Update Brings HTTP Vulnerability Fix, Other Bug Fixes

Advertisement
By Tasneem Akolawala | Updated: 21 January 2019 14:20 IST
Highlights
  • ES File Explorer has quickly rolled out a fix for the HTTP vulnerability
  • Reported last week, vulnerability allowed easy phone access to hackers
  • ES File Explorer v4.1.9.9 update with the fix is available on Google Play

ES File Explorer was reported to have HTTP vulnerability in LAN

Just last week, an HTTP vulnerability was reported within ES File Explorer - a popular app used by many to manage phone storage. The vulnerability allegedly gave hackers easy access to phone's files, and all the victim had to do was open the app once to be exposed to it. Developers of ES File Explorer were quick to respond to this newfound bug, and within days of the reported vulnerability, a fix for the same has been issued. The update ES File Explorer v4.1.9.9 version is now available on Google Play, and all users are recommended to download it.

The changelog for the ES File Explorer v4.1.9.9 update states that the HTTP vulnerability in LAN has been fixed, alongside some other known bug fixes as well. The new v4.1.9.9 update also fixes a problem "that the music player part could not create a song list". A spokesperson also confirmed the fixes to Android Police, "The issue of unauthorised copying of files has been fixed by removing the corresponding code. The way a man-in-the-middle attack is avoided by the way the server upgrades."

We recommend all users to update to the latest version of ES File Explorer. The update is available to download for free on the Play Store, and as we mentioned, comes within days of the vulnerability being reported. The company had reportedly issued a fix last week itself, and was waiting for the Google market to pass the review. The developers told Android Police, "We have fixed the http vulnerability issue and released it. Waiting for the Google market to pass the review." And now finally the update with the fix is out for download.

Advertisement

According to security researcher who goes by the pseudonym Eliot Alderson, ES File Explorer used to start an HTTP server on port 59777, which left your phone accessible to anyone on the same local network to exploit it. The attacker can then use that port to inject a JSON payload and list out the files you have and even download them. If you happen to still use the app in in v4.1.9.7.4 and lower, then its best to update immediately, or connect only to highly trusted networks, or look for other alternatives.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: ES File Explorer
Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  4. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  5. Airtel Discontinues These Prepaid Recharge Packs in India
  6. OTT Releases of the Week (Dec 1 – Dec 7): Know What to Watch
  7. Apple Announces App Store Awards 2025 Winners: Check List
  8. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  9. Nothing Phone 3a Lite Goes on Sale in India at This Price
  10. Here's What India Searched For the Most on Google in 2025
  1. Netflix to Buy Warner Bros. in $72 Billion Cash, Stock Deal
  2. George Clooney-Starrer Jay Kelly Now Streaming on Netflix: All You Need to Know
  3. Google's Year in Search 2025 Reveals Gemini 3, Nano Banana Pro and Other AI Search Features Launched in India 2025
  4. Poco C85 5G Display Specifications Confirmed Days Ahead of Launch in India: See Expected Specifications
  5. Polar Loop Screen-Free Fitness Tracker Launched in India With Up to Eight Days of Battery Life: Price, Specifications
  6. Xiaomi 17S Pro Said to Be in Development, Could Launch After Xiaomi 17 Ultra Debuts
  7. Motorola Edge 70 India Launch Teased; Flipkart Availability Confirmed: Expected Specifications, Features
  8. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  9. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  10. CFTC Clears Path for Spot Crypto Trading on Regulated Platforms for the First Time
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.