LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without needing an internet connection. In versions 1.16.1 and below, a critical Man-in-the-Middle (MitM) vulnerability in the software's discovery protocol allows an unauthenticated attacker on the same local network to impersonate legitimate devices, silently intercepting, reading, and modifying any file transfer. This can be used to steal sensitive data or inject malware, like ransomware, into files shared between trusted users. The attack is hardly detectable and easy to implement, posing a severe and immediate security risk. This issue was fixed in version 1.17.0.
The vulnerability results from lack of proper device identity verification (CWE-345) and the possibility of intercepting communication in the device discovery channel (CWE-300). An attacker present on the same local network can advertise themselves as a legitimate LocalSend device, persuading victims to establish a connection with them instead of the intended recipient. The attack is difficult to detect by the user and simple to implement.
An attacker can silently intercept, read, and modify any files transmitted between LocalSend application users, which may lead to theft of sensitive data or injection of malicious software (e.g., ransomware) into transferred files.
Update the LocalSend application to version 1.17.0 or later, where the issue has been fixed. The patch is available in the official project repository on GitHub (tag v1.17.0).
LocalSend in versions 1.16.1 and earlier
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XLocalsend
APPLocalsend< 1.17.0