ES File Explorer Vulnerability Allows Access to Phone's Files From Local Network: Report

Advertisement
By Gagan Gupta | Updated: 17 January 2019 11:41 IST
Highlights
  • The app needs to be run just once for this vulnerability to be active
  • All the vulnerable phone's files can be listed and downloaded
  • This affects ES File Explorer v4.1.9.7.4 and lower

ES File Explorer has over a hundred million downloads on Google Play

ES File Explorer has been one of the most popular ways to navigate and manage your phone's storage. Though there are in build file managers in most modern Android devices, the app still have over a hundred million downloads on Google Play alone. The problem is that the app has been getting bloated with additional functions that frankly no one asked for, which has also been the reason for the app's barrage of negative reviews on the Play Store. To add to the problems, security researcher with Mr. Robot inspired pseudonym Elliot Alderson recently claimed the app makes your phone's files easily vulnerable to data theft.

In his tweet Eliot Alderson states "With more than 100,000,000 downloads ES File Explorer is one of the most famous #Android file manager. The surprise is: if you opened the app at least once, anyone connected to the same local network can remotely get a file from your phone". He also attached the video embedded below to demonstrate his point.

 

Advertisement

ES File Explorer starts an HTTP server on port 59777, which leaves makes your phone accessible to anyone on the same local network to exploit it, the researcher claimed. The attacker can then use that port to inject a JSON payload and list out the files you have and even download them.

This vulnerability is claimed to exist in v4.1.9.7.4 (which is the current version of the app on the Google Play Store at the time of writing), and lower. If you happen to use the app, then its best to connect only to highly trusted networks, or look for an alternative at least until there's an update that resolves this issue.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme Neo 8 Key Specifications Confirmed Ahead of January 22 Launch
  2. Arc Raiders Will Get Multiple New Maps This Year, Says Embark
  3. Terminally Ill Fan May Be Able to Play GTA 6 Ahead of Release
  4. Samsung Galaxy S26 Ultra Colourways Spotted in Leaked SIM Tray Images
  5. Viruses and Bacteria Evolve Differently in Space, ISS Study Finds
  6. Apple Could Bring LTPO+ Panel, Under-Display Face ID Tech to iPhone 18
  7. Here's How Much the Realme P4 Power Could Cost in India
  8. Sarvam Maya OTT Release: Know Everything About This Malayalam Fantasy Drama Film
  9. JioHotstar Announces Monthly Subscription Plans Across All Tiers
  1. Global RAM Shortage Is Reportedly Causing GPU, Storage Drive Prices to Skyrocket
  2. Viruses and Bacteria Evolve Differently in Space, ISS Study Finds
  3. Rockstar Games Said to Have Granted a Terminally Ill Fan's Wish to Play GTA 6
  4. Oppo K15 Turbo Series Tipped to Feature Built-in Cooling Fans; Oppo K15 Pro Model Said to Get MediaTek Chipset
  5. Samsung Galaxy Z Fold 8 Said to Feature Dual Ultra-Thin Glass OLED Panel to Reduce Crease Visibility
  6. Realme Neo 8 Key Specifications Including 8,000mAh Battery, Ultrasonic Fingerprint Sensor Confirmed
  7. Astronomers Find Massive Iron-Rich Feature Lurking Under the Ring Nebula
  8. Asus Reportedly Halts Smartphone Launches ‘Temporarily’ to Focus on AI Robots, Smart Glasses
  9. JioHotstar Announces Monthly Subscription Plans Across Mobile, Super, and Premium Tiers
  10. New Solid-State Freezer Could Replace Climate-Harming Refrigerants
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.