ES File Explorer Vulnerability Allows Access to Phone's Files From Local Network: Report

Advertisement
By Gagan Gupta | Updated: 17 January 2019 11:41 IST
Highlights
  • The app needs to be run just once for this vulnerability to be active
  • All the vulnerable phone's files can be listed and downloaded
  • This affects ES File Explorer v4.1.9.7.4 and lower

ES File Explorer has over a hundred million downloads on Google Play

ES File Explorer has been one of the most popular ways to navigate and manage your phone's storage. Though there are in build file managers in most modern Android devices, the app still have over a hundred million downloads on Google Play alone. The problem is that the app has been getting bloated with additional functions that frankly no one asked for, which has also been the reason for the app's barrage of negative reviews on the Play Store. To add to the problems, security researcher with Mr. Robot inspired pseudonym Elliot Alderson recently claimed the app makes your phone's files easily vulnerable to data theft.

In his tweet Eliot Alderson states "With more than 100,000,000 downloads ES File Explorer is one of the most famous #Android file manager. The surprise is: if you opened the app at least once, anyone connected to the same local network can remotely get a file from your phone". He also attached the video embedded below to demonstrate his point.

 

Advertisement

ES File Explorer starts an HTTP server on port 59777, which leaves makes your phone accessible to anyone on the same local network to exploit it, the researcher claimed. The attacker can then use that port to inject a JSON payload and list out the files you have and even download them.

Advertisement

This vulnerability is claimed to exist in v4.1.9.7.4 (which is the current version of the app on the Google Play Store at the time of writing), and lower. If you happen to use the app, then its best to connect only to highly trusted networks, or look for an alternative at least until there's an update that resolves this issue.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Phone 4a, Phone 4a Pro Launched in India at This Price
  2. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  3. Lava Bold 2 5G India Launch Teased; Company Teases Design Ahead of Debut
  4. Nothing Phone 4a vs Motorola Edge 70: Price in India, Features Compared
  5. OnePlus 16, iQOO 16, Redmi K100 Pro Max Tipped to Launch at Higher Prices
  6. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  7. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  8. WhatsApp Plus Could Soon Let You Pay to Access These Features
  9. Infinix Note 60 Ultra With Pininfarina Design Launched at MWC 2026
  1. Samsung Galaxy A37 5G and Galaxy A57 5G Specifications Reportedly Leaked in Full Ahead of Launch
  2. ISS Crew Prepares to Send Japan’s HTV-X1 Cargo Spacecraft Back to Earth After Four Months
  3. OpenAI’s Codex App Is Now Available on Windows, Can Be Downloaded via Microsoft Store
  4. OpenAI Teases GPT-5.4 AI Model Launch Just a Day After Releasing GPT-5.3 Instant
  5. Nothing Headphone (a) Launched With Adaptive ANC, Customisable Controls: Price, Specifications
  6. Granny OTT Release Date: When and Where to Watch the Village Mystery Thriller Online?
  7. Andhaka OTT Release: Where to Watch the Telugu Drama-Thriller Online?
  8. Pookie OTT Release: When and Where to Watch Vijay Antony’s Romantic Drama Online?
  9. WhatsApp Plus Paid Subscription Reportedly in Development With Additional Customisation Options, Up to 20 Pinned Chats
  10. Samsung Patent Hints at Potential Clamshell-Style Foldable With Two Cover Displays
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.