Apple Find My network could be abused to siphon data from nearby devices GPS


Apple’s device location tracking service, Find My, can be abused to siphon data from nearby devices and deliver it across the globe, a new report claims.
In a blog post, cybersecurity company Positive Security sets out a proof-of-concept exploit, called Send My. The exploit demonstrates that the Bluetooth Low Energy (BLE) broadcasts on which the Find My network is built can be manipulated to lift small quantities of arbitrary data, without even the need for an internet connection.
Made possible by special ESP32 firmware that turns a microcontroller into a modem that taps into the network of devices, the exploit could also in theory be used to rinse mobile data plans, the post suggests.
Apple Find My network
The Apple Find My network is dependent on a crowdsource information system, rather than GPS, to locate iOS, macOS and watchOS devices – and now, AirTags too.
If someone opts into the program, their devices will begin to communicate over BLE with other Apple technology in the area. And the volume of Apple products in circulation means these device pings can be used to build an accurate map of the location of each piece of kit.
As part of this process, however, the communications between devices are also relayed to Apple’s servers, from where the information could be later retrieved. In this case, Positive Security developed a macOS app capable of retrieving, decoding and displaying this data.
“Such a technique could be employed by small sensors in uncontrolled environments to avoid the cost and power consumption of mobile internet,” explained Fabian Bräunlein, co-founder of Positive Security. “It could also be interesting for exfiltrating data from Faraday-shielded sites that are occasionally visited by iPhone users.”
While the quantity of data that could be lifted via this method is limited and the latency is poor (up to 60 minutes), it’s thought that advanced threat actors may be able to leverage the exploit to good effect.
According to Positive Security, the privacy-centric way in which the Find My network has been architected means it may be impossible for Apple to block off the attack vector.
Apple did not respond to a request for comment.
- Here’s our list of the best VPN services right now
Via The Register
Apple’s device location tracking service, Find My, can be abused to siphon data from nearby devices and deliver it across the globe, a new report claims. In a blog post, cybersecurity company Positive Security sets out a proof-of-concept exploit, called Send My. The exploit demonstrates that the Bluetooth Low Energy…
Recent Posts
- Fraudsters seem to target Seagate hard drives in order to pass old, used HDDs as new ones using intricate techniques
- Hackers steal over $1bn in one of the biggest crypto thefts ever
- Annapurna’s 2025 lineup of indie games is full of tea and T-poses
- Google Drive gets searchable video transcripts
- Andor is on the offensive in latest season 2 trailer
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010