Skip to main content

Apple has yet to patch vital security flaw in its Find My network

Person holding an Apple AirTag.
Apple

Apple’s Find My network is a powerful tool for tracking the location of your devices, but it has a major security vulnerability that hasn’t been patched. Researchers at George Mason University discovered the network can be exploited to track almost any Bluetooth device — not just an AirTag or iPhone — through a combination of Apple’s network and a device’s Bluetooth address.

“It’s like transforming any laptop, phone, or even gaming console into an Apple AirTag – without the owner ever realizing it,” said lead author Junming Chen. “And the hacker can do it all remotely, from thousands of miles away, with just a few dollars.” 

Recommended Videos

To understand the exploit, you need to understand how the Find My network operates. Take an AirTag as an example; it pings nearby Apple devices with a Bluetooth signal, and that signal is anonymously sent to the Apple Cloud. The key to the exploit lies in this anonymity.

Apple's Find My Devices website showing a list of devices against a background map.
Jesse Hollington / Digital Trends / Apple

Since the Find My network relies on encrypted data rather than administrative privileges, the researchers were able to build a key that adapts on the fly. They dubbed it “nRootTag,” and the terrifying part is that it has a 90% success rate.

Please enable Javascript to view this content

The team tested the exploit on a wide range of devices to unsettling success. They pinpointed the location of a computer to within 10 feet and identified an airplane’s flight path (and number) by tracking a gaming console a passenger had taken aboard.

While the experiment highlights the power of the Find My network, it also illustrates how easily a bad actor could gain access to sensitive information. AirTags have been used to track people in the past — one of the reasons Apple intends to make the speaker tougher to remove in the AirTag 2 — but nRootTag goes beyond that. The team traced VR headsets, smart TVs, and numerous other devices with relative ease.

Find My app icon in iOS 15.
Apple

Qiang Zeng, another member of the research team, highlighted a particularly awful use. “While it is scary if your smart lock is hacked, it becomes far more horrifying if the attacker also knows its location. With the attack method we introduced, the attacker can achieve this.” 

The team alerted Apple of the security flaw in July 2024, and the company has since acknowledged it in update notes. However, no patch has been issued. The exploit takes advantage of the core functionality of the Find My network, and introducing a fix that doesn’t somehow impair the location-tracking functionality will take time — potentially years, according to the team.

As for what to do in the meantime, Chen recommends keeping all devices and software up to date and monitoring anything that requests Bluetooth permission, especially if the app doesn’t need it.

Patrick Hearn
Patrick Hearn writes about smart home technology like Amazon Alexa, Google Assistant, smart light bulbs, and more. If it's a…
AirPods to gain Find My function, and possible respiratory monitoring
AirPods 2 Charging Case opened on a table.

Apple's iconic white true wireless earbuds are slated to get several new functions with the upcoming general release of iOS 15. But the most important of these -- at least from the perspective of folks who have a tendency to forget where they left their earbuds -- is the ability to connect a set of AirPods to your Apple ID, which could give you the same ability to locate them that Apple users currently enjoy with their iPhones, iMacs, MacBooks, and iPads.

First spotted in the code for an iOS 15 beta release by 9to5Mac, it looks like you'll be able to register AirPods Pro and AirPods Max to your Apple ID (sorry regular AirPods owners). You'll then be able to leverage Apple's enormous Find My network to locate your missing earbuds or headphones. Unfortunately, the same beta code also suggests that, unlike the locking/remote wipe feature that Apple offers for its computing devices, there's no way to prevent someone who finds your audio gear from removing the Apple ID association and making it their own.

Read more
Move over iPhone, here’s a phone with a massive battery and built-in projector
Tank 3 Pro in someone's hand.

Even the biggest flagship smartphones can't compare to the size of the 8849 Tank 3 Pro, a rugged smartphone with a ridiculously-huge 23,800mAh battery. Yes, you read that right. It's not a typo. The phone also a built-in projector that can reach brightness levels of 100 lumens for watching your favorite content outside.

The Tank 3 Pro is designed to go toe-to-toe with even the toughest environments while providing you with all the power you could possibly need. It starts at 512GB of storage (expandable up to 2TB) and 36 GB of RAM. It also works with 5G and has a 200MP main camera alongside a 64MP night-vision camera.

Read more
The distraction-busting Light Phone III launches at the end of this month
Light Phone 3

Introducing the Light Phone III

If you're searching for a phone that lets you stay in touch but keeps things simple, the Light Phone III is the device for you. This phone is produced by Light, a company whose mission statement is to create "things that serve you, not the other way around." The latest model launches at the end of this month on March 27.

Read more