Security expert hijacks Apple's Find My network to share data with a Linux device
Researcher tricks Apple's Find My into feeding live location data to a Linux box, with no Mac or iPhone required.
A security researcher has successfully registered a Linux device as a trusted node on Apple's Find My network, allowing it to receive live people-location data meant for Apple devices like iPhones and iPads. This technique, discovered by Zerotistic, required a Linux box to obtain an Apple Identity Services (IDS) certificate, device and messaging credentials, and push notification tokens.
Once registered, the Linux device could subscribe to six different subservices to function as part of Apple's ecosystem. The process, completed within a week, involved crafting a certificate signing request, obtaining a signed certificate, and subscribing to the necessary services. The researcher then obtained a location key from a friend's Apple device and shared it with the Linux box, which masqueraded as a trusted Apple device.
While the technique requires consent from the friend to track their location, it demonstrates that Apple's security around Find My is based on a protocol rather than cryptographic barriers. Apple has not yet commented on the potential vulnerabilities exposed by this research.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.