{
  "id": 3564822,
  "title": "Security expert hijacks Apple's Find My network to share data with a Linux device",
  "url": "https://urgent.news/2026/08/26/security-expert-hijacks-apples-find-my-network-to-share-data-with-a",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-26T18:20:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/security-expert-hijacks-apples-find-my-network-to-share-data-with-a-linux-device"
  },
  "original_language": "en",
  "account": "A security researcher has successfully registered a Linux device as a trusted node on Apple's Find My network, allowing it to receive live people-location data meant for Apple devices like iPhones and iPads. This technique, discovered by Zerotistic, required a Linux box to obtain an Apple Identity Services (IDS) certificate, device and messaging credentials, and push notification tokens. Once registered, the Linux device could subscribe to six different subservices to function as part of Apple's ecosystem. The process, completed within a week, involved crafting a certificate signing request, obtaining a signed certificate, and subscribing to the necessary services. The researcher then obtained a location key from a friend's Apple device and shared it with the Linux box, which masqueraded as a trusted Apple device. While the technique requires consent from the friend to track their location, it demonstrates that Apple's security around Find My is based on a protocol rather than cryptographic barriers. Apple has not yet commented on the potential vulnerabilities exposed by this research.",
  "summary": "Researcher tricks Apple's Find My into feeding live location data to a Linux box, with no Mac or iPhone required.",
  "key_points": [
    "Security researcher registered Linux device on Apple's Find My network.",
    "Linux device received live people-location data meant for Apple devices.",
    "Technique demonstrated vulnerabilities in Apple's security around Find My."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}