Skip to main content

Apple has yet to patch vital security flaw in its Find My network

Person holding an Apple AirTag.
Apple

Apple’s Find My network is a powerful tool for tracking the location of your devices, but it has a major security vulnerability that hasn’t been patched. Researchers at George Mason University discovered the network can be exploited to track almost any Bluetooth device — not just an AirTag or iPhone — through a combination of Apple’s network and a device’s Bluetooth address.

“It’s like transforming any laptop, phone, or even gaming console into an Apple AirTag – without the owner ever realizing it,” said lead author Junming Chen. “And the hacker can do it all remotely, from thousands of miles away, with just a few dollars.” 

Recommended Videos

To understand the exploit, you need to understand how the Find My network operates. Take an AirTag as an example; it pings nearby Apple devices with a Bluetooth signal, and that signal is anonymously sent to the Apple Cloud. The key to the exploit lies in this anonymity.

Apple's Find My Devices website showing a list of devices against a background map.
Jesse Hollington / Digital Trends / Apple

Since the Find My network relies on encrypted data rather than administrative privileges, the researchers were able to build a key that adapts on the fly. They dubbed it “nRootTag,” and the terrifying part is that it has a 90% success rate.

The team tested the exploit on a wide range of devices to unsettling success. They pinpointed the location of a computer to within 10 feet and identified an airplane’s flight path (and number) by tracking a gaming console a passenger had taken aboard.

While the experiment highlights the power of the Find My network, it also illustrates how easily a bad actor could gain access to sensitive information. AirTags have been used to track people in the past — one of the reasons Apple intends to make the speaker tougher to remove in the AirTag 2 — but nRootTag goes beyond that. The team traced VR headsets, smart TVs, and numerous other devices with relative ease.

Find My app icon in iOS 15.
Apple

Qiang Zeng, another member of the research team, highlighted a particularly awful use. “While it is scary if your smart lock is hacked, it becomes far more horrifying if the attacker also knows its location. With the attack method we introduced, the attacker can achieve this.” 

The team alerted Apple of the security flaw in July 2024, and the company has since acknowledged it in update notes. However, no patch has been issued. The exploit takes advantage of the core functionality of the Find My network, and introducing a fix that doesn’t somehow impair the location-tracking functionality will take time — potentially years, according to the team.

As for what to do in the meantime, Chen recommends keeping all devices and software up to date and monitoring anything that requests Bluetooth permission, especially if the app doesn’t need it.

Patrick Hearn
Patrick Hearn writes about smart home technology like Amazon Alexa, Google Assistant, smart light bulbs, and more. If it's a…
Forget AirTags. This backpack has Apple’s ‘Find My’ tech built directly into it
Targus backpack with Apple Find My support

Computer accessory maker Targus wants to make misplacing your backpack a thing of the past. At CES 2022 the company introduced a new backpack you can track with your iPhone -- and the best part is you don’t need Apple’s AirTag for it.

The Targus Cypress Hero EcoSmart Backpack comes in-built with the technology behind Apple’s puck-sized tracker. This means you can pull up the Find My app on an iPhone, iPad, Mac, and/or Apple Watch and instantly trace down the backpack’s whereabouts. It houses a tracking module that constantly beams the backpack’s location and, thanks to a rechargeable battery, lasts over a year in one go.

Read more
Apple finally makes it harder to stalk Android users with its new Tracker Detect app
Apple Airtag in different polyurethane and leather key rings and loops

Apple has announced and released a new AirTags tracker app for Android called Tracker Detect. This has been done to resolve one of the privacy issues inadvertently introduced with AirTags earlier this year -- the ability to track someone without their knowledge. Once it was installed and a scan was initiated, the app was able to highlight unknown AirTag trackers nearby, essentially revealing the location of strangers and opening the door for planting an AirTag on someone without their knowledge to keep tabs on them.

AirTags were released earlier in the year as a rival to Tile and other Bluetooth trackers. They leveraged Apple's Find My network to help users track lost items by communicating with a combination of Bluetooth and Ultra Wideband. Unlike Tile trackers, they could also be used to geolocate lost items. However, AirTags also came with an unintended consequence: They could allow people to be tracked without their knowledge by simply tagging their clothes or personal property. Apple users would be protected against it as an iPhone running iOS 15 would be able to detect that an unknown AirTag was found moving with you, but that was not an option for Android devices.

Read more
AirPods to gain Find My function, and possible respiratory monitoring
AirPods 2 Charging Case opened on a table.

Apple's iconic white true wireless earbuds are slated to get several new functions with the upcoming general release of iOS 15. But the most important of these -- at least from the perspective of folks who have a tendency to forget where they left their earbuds -- is the ability to connect a set of AirPods to your Apple ID, which could give you the same ability to locate them that Apple users currently enjoy with their iPhones, iMacs, MacBooks, and iPads.

First spotted in the code for an iOS 15 beta release by 9to5Mac, it looks like you'll be able to register AirPods Pro and AirPods Max to your Apple ID (sorry regular AirPods owners). You'll then be able to leverage Apple's enormous Find My network to locate your missing earbuds or headphones. Unfortunately, the same beta code also suggests that, unlike the locking/remote wipe feature that Apple offers for its computing devices, there's no way to prevent someone who finds your audio gear from removing the Apple ID association and making it their own.

Read more