ES File Explorer Vulnerability Allows Access to Phone's Files From Local Network: Report

Advertisement
By Gagan Gupta | Updated: 17 January 2019 11:41 IST
Highlights
  • The app needs to be run just once for this vulnerability to be active
  • All the vulnerable phone's files can be listed and downloaded
  • This affects ES File Explorer v4.1.9.7.4 and lower
ES File Explorer Vulnerability Allows Access to Phone's Files From Local Network: Report

ES File Explorer has over a hundred million downloads on Google Play

ES File Explorer has been one of the most popular ways to navigate and manage your phone's storage. Though there are in build file managers in most modern Android devices, the app still have over a hundred million downloads on Google Play alone. The problem is that the app has been getting bloated with additional functions that frankly no one asked for, which has also been the reason for the app's barrage of negative reviews on the Play Store. To add to the problems, security researcher with Mr. Robot inspired pseudonym Elliot Alderson recently claimed the app makes your phone's files easily vulnerable to data theft.

In his tweet Eliot Alderson states "With more than 100,000,000 downloads ES File Explorer is one of the most famous #Android file manager. The surprise is: if you opened the app at least once, anyone connected to the same local network can remotely get a file from your phone". He also attached the video embedded below to demonstrate his point.

 

ES File Explorer starts an HTTP server on port 59777, which leaves makes your phone accessible to anyone on the same local network to exploit it, the researcher claimed. The attacker can then use that port to inject a JSON payload and list out the files you have and even download them.

Advertisement

This vulnerability is claimed to exist in v4.1.9.7.4 (which is the current version of the app on the Google Play Store at the time of writing), and lower. If you happen to use the app, then its best to connect only to highly trusted networks, or look for an alternative at least until there's an update that resolves this issue.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi 15s Pro Design, Camera Details Teased Ahead of Launch Today
  2. Tecno Pova Curve 5G India Launch Date Announced
  3. Sam Altman Reportedly Drops Clues About 'Secret' AI Device With Jony Ive
  4. Realme Neo 7 Turbo Launch Date Confirmed; Teased to Run on This New Chipset
  5. Honor 400 Series Confirmed to Get Six Years of Android Updates
  6. Mistral's Coding Agent Devstral Outperforms OpenAI's GPT-4.1 Mini
  7. Vi Rolls Out 'Nonstop Hero' Plan With Truly Unlimited Data and Calls
  1. SpaceX Successfully Launches 23 Starlink Satellites on Brand-New Falcon 9 Rocket
  2. Polaris Wasn’t Always the North Star: How Earth’s Wobble Shifts the Celestial Pole
  3. Scientists Warn of Inadequate Solar Storm Forecasting: What You Need to Know
  4. NASA’s Perseverance Explores Mars' Oldest Rocks in Krokodillen Region
  5. New Study Uses AI to Reveal Dry Origins of Mars’ Mysterious Slope Streaks
  6. Ancient 14,000-Year-Old Solar Storm Revealed as Strongest Ever Recorded in Earth’s History
  7. New Study Confirms TeV Halos Are Common in Middle-Aged Pulsars
  8. Capuchin Monkeys Abduct Baby Howler Monkeys on Panama’s Jicarón Island, New Study Reveals
  9. Sneaky Links: Dating After Dark Now Streaming on Netflix: What You Need to Know
  10. Devika & Danny OTT Release Date Revealed: When and Where to Watch It Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.