started · updated
Apple Find My network vulnerability demonstrated using Linux device
A security researcher known as “Zerotistic” has demonstrated a method to register a Linux device within Apple’s Find My network to access shared location data. The exploit allows a non-Apple device to act as a trusted device, receiving real-time location updates from users who have shared their information.
The researcher achieved this in less than a week by reverse-engineering Apple’s communication protocols and utilizing specific certificates and public keys. Notably, the process did not require a jailbreak, a detected key, or a Mac.
While the demonstration highlights a way to use the network in an unintended manner, the researcher noted significant limitations. The exploit requires the explicit consent of the person sharing their location, meaning it cannot be used to track unknown users. The complexity of Apple’s proprietary protocols and the requirement for specific certificates suggest that the system remains highly protected and is not easily accessible to casual users.
Entities
Apple · Linux · Zerotistic