SHAREit Vulnerabilities Could Allow Remote Code Execution, Leak Sensitive Data

SHAREit was among the 59 apps banned in June 2020 in India because it was made by Chinese developers.

Advertisement
By Vineet Washington | Updated: 18 February 2021 16:22 IST
Highlights
  • SHAREit vulnerabilities could allow attackers to install malicious apps
  • Attackers could perform remote code execution
  • SHAREit was banned in India in June 2020

SHAREit is not available on Google Play in India

Photo Credit: Google Play

SHAREit app has been found to have vulnerabilities that can be exploited to leak sensitive data and execute arbitrary code. A cyber-security software company has discovered “several vulnerabilities” in SHAREit and states that these are most likely unintended flaws in the app. The company says it has informed Google of these vulnerabilities. In India, SHAREit was banned back in June last year along with 58 other apps including TikTok, UC Browser, WeChat, and others. These apps had one common factor – they were all of Chinese origin.

Trend Micro, a cyber-security software company, discovered various vulnerabilities in file sharing app SHAREit. To do so, it built a proof-of-concept (POC) code which showed that any app can invoke a StartActivity function in SHAREit, including its internal (non-public) and external app activities. It was also found that any third-party entity can gain temporary read/ write access to the content of the person who is sharing the data. The POC code read WebView cookies and it was noted that this code can be used to write any files in the app's data folder. This means that the files can be overwritten as well.

Attackers could also craft a fake vdex/ odex file – that SHAREit generates when first launched – and then replace those files due to the vulnerability, allowing the attacker to perform code execution.

Advertisement

Trend Micro found that SHAREit provides a feature that can install an APK with the file name suffix ‘sapk' that can be used to install a malicious app. This would enable a limited Remote Code Execution (RCE) when the user clicks on a URL (SHAREit has deep links using URL leading to specific features in the app).

Advertisement

The company built an href attribute in HTML to verify RCE with Google Chrome browser. Chrome was coded to call SHAREit to download the sapk from http://gshare.cdn.SHAREitgames.com and since it supports HTTP protocol, the company found it can be replaced by simulating a man-in-the-middle (MitM) attack. This would allow malware to be downloaded to the user's phone.

Additionally, SHAREit is susceptible to a man-in-the-disk (MITD) attack as when a user downloads a certain app through SHAREit, it goes to a folder in an external directory. This means that the app can access the directory with SD card write permission.

Advertisement

Trend Micro recommends regularly updating mobile operating systems and the apps in order to try and prevent such vulnerabilities negatively affecting you. The Indian government banned SHAREit and 58 other apps back in June 2020 as they were of Chinese origin.


Is Mi 10i a OnePlus Nord killer? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

 

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: SHAREit, Google, Chrome, Google Play
Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Note 15 Pro Series 5G Launched in India With These Features
  2. Realme P4 Power 5G With 10,001mAh Battery Arrives in India: See Price
  3. QCY SP7 Bluetooth Speaker Review
  4. Vivo X200T Review
  5. Adobe Express Premium Is Now Free for One Year for All Airtel Users
  6. WhatsApp Could Soon Add a Subscription Plan With These Exclusive Features
  7. iQOO 15R Dark Knight Colourway Teased Weeks Ahead of Launch in India
  8. Samsung Galaxy S26 Ultra Could Cost Less than Its Predecessor
  9. Microsoft Reports Declining Gaming Revenue, Xbox Hardware Sales
  10. iQOO 15 Ultra Lands on Geekbench Ahead of Launch on February 4
  1. Global Smartphone SoC Shipments to Decline by 7 Percent in 2026 Amid Rising Memory Costs: Counterpoint
  2. Thursday Special Now Available For Streaming: Where to Watch Award-Winning Short Film by Shoojit Sircar
  3. Sarvam Maya OTT Release Date: When and Where to Watch This Malayalam Fantasy Drama Film Online?
  4. iQOO 15 Ultra Visits Geekbench With Impressive Performance Benchmark Scores
  5. iQOO 15R Dark Knight Colour Option Confirmed: Expected Specifications, Features
  6. Microsoft Reports Declining Gaming Revenue, Xbox Hardware Sales
  7. WhatsApp Reportedly Working on Subscription Plan That Offers Exclusive Features, Customisation Options
  8. Google Introduces New Gemini AI Tools, Practice Tests For JEE Main Aspirants
  9. OpenAI Introduces Prism, a Free AI Workspace for Scientific Collaboration
  10. Samsung's 'Next-Generation' AR Glasses With Multimodal AI Capabilities Confirmed to Launch in 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.