{
  "id": 2188972,
  "title": "Researcher tricks Apple’s Find My into sharing location data with Linux",
  "url": "https://urgent.news/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux-2188972",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-20T16:10:54.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux/5290496"
  },
  "original_language": "en",
  "account": "A 22-year-old security researcher, known as \"Zerotistic,\" has discovered a method to register a Linux device into Apple's Find My network and access live location data from it. Find My is Apple's app designed to help users locate items, people, and even themselves using a network of Apple devices. However, this method allows access to location data from non-Apple devices that have previously shared their locations with the Apple account owner. The researcher first linked the Linux machine to their Apple account using Apple's GrandSlam authentication protocol and an Apple Identity Services device certificate. They then crafted a custom certificate signing request (CSR) following specific requirements such as using PKCS#10 format, a 2048-bit RSA key, and SHA-1 signing. Apple signed the CSR, granting the Linux device the necessary identity certificate to register its public key to the researcher's Apple account. After registration, the Linux machine had to prove its capability to receive Find My location data by subscribing to six subservices, defining supported encryption types, and providing public keys. Once registered, the researcher used a SubscribeAndFetch request to obtain encrypted location keys from a friend's Apple device, which were then decrypted and decoded using a Linux script. The researcher managed to develop the method in under a week, but Apple did not yet respond to inquiries regarding the discovered vulnerability.",
  "summary": "Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Researcher tricks Apple’s Find My into sharing location data with Linux",
        "url": "https://urgent.news/2026/08/20/researcher-tricks-apples-find-my-into-sharing-location-data-with-linux",
        "published": "2026-08-20T16:10:54.000Z"
      },
      {
        "outlet": "Seeking Alpha News",
        "title": "Apple App Store net revenues see dip Y/Y, monthly data shows: Morgan Stanley",
        "url": "https://urgent.news/2026/08/20/apple-app-store-net-revenues-see-dip-y-y-monthly-data-shows-morgan",
        "published": "2026-08-20T17:47:37.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}