Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

Security expert hijacks Apple's Find My network to share data with a Linux device | TechRadar

A 'trusted' Linux device can impersonate an Apple device and access already-shared Find My locations Discover insights about security expert hijacks apple's fin

TechnologyInnovationBest PracticesGuideTutorial
Security expert hijacks Apple's Find My network to share data with a Linux device | TechRadar
Listen to Article
0:00
0:00
0:00

Security expert hijacks Apple's Find My network to share data with a Linux device | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Security expert hijacks Apple's Find My network to share data with a Linux device

A 'trusted' Linux device can impersonate an Apple device and access already-shared Find My locations

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Apple's Find My i Phone displayed in settings (Image credit: Future / Axel Metz)

Researcher registers Linux machine as a trusted device on Apple's Find My network and pulled live people-tracking data that Apple normally reserves for its own hardware

The work is not a mass-surveillance exploit: it is limited in scope and only reads a location share that a friend had already agreed to, and it cannot silently locate arbitrary Apple users

The approach took less than a week of protocol reverse engineering, and Apple has maintained silence on queries about the technique employed

Apple keeps the full Find My experience locked to its own devices, but a recent attempt by security researchers suggests that wall may be a relatively weak barrier to entry.

A 22-year-old security researcher who goes by "Zerotistic" documented how they registered an ordinary Linux machine as a trusted node on Apple's network and used its new status to receive live people-location data that Apple otherwise shares only with its own devices, such as i Phones and i Pads.

Find My, Apple's catch-all tool for locating hardware such as Air Tags, i Phones, and i Pads, also lets people share their whereabouts with family and friends, and while Apple has historically guarded this particular feature very closely, it is also the same one the security researcher targeted to introduce a device that Apple does not otherwise have complete control over as part of its ecosystem.

An interesting trick that still requires consent to get the job done

The task is not an easy one to begin with: convincing Apple's back end that a Linux process was a legitimate Apple device that was part of its ecosystem and therefore could be trusted with information shared via the Find My platform required a lot of trial and error to get going.

It is important to clarify here that Apple's system is not exactly compromised here; the approach still requires a friend to share data that the Linux client that the security researcher built can then read.

Apple 'Find My' mystery keeps sending people to one innocent person's house

New 'Anony Mous' phishing campaign targets i Phone users with fake AI Apple support calls

Experts claim to have found more weaknesses in Apple's Gatekeeper tool

Apple currently sends people-location data over its private Push Notification service only after it trusts that the receiving machine belongs to the account and can handle the data. This means the Linux machine would have to speak Apple's private language to query its servers and process the information it received.

It involved obtaining an Apple Identity Services (IDS) certificate, a specialized device and messaging credential Apple's internal framework uses to link an Apple Account to specific hardware, end-to-end encryption keys, and push notification tokens. This meant crafting a certificate signing request and sending it to a legacy Apple enrollment endpoint.

The researcher then issued a Subscribe And Fetch request that provided an encrypted location key from his friend's Apple device to the Linux box, masquerading as one.

What might concern Apple is how fast things moved: the whole pipeline came together in a week. It also didn't require a jailbreak, a leaked key, or even a Mac to do the job. Instead, open-source clients and decompiled daemons were the norm, with a trial-and-error approach that eventually paid off.

The technique has its limitations: attacks can not target a stranger, and consent is required to track even one's friends. It shows that Apple's boundary around Find My stems from an obscure protocol it enforces rather than a cryptographic lock; once a device acts like it is from Apple, the ecosystem treats it as a family member rather than an untrusted node.

Apple has yet to respond to media queries about whether it plans to address the demonstrated trick or patch the loop in the near future.

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.

You must confirm your public display name before commenting

Shiny Hunters hackers claim to have hit data center provider used by Microsoft and Meta

FDA approves world-first CGM wearable in diabetes 'breakthrough'

Nvidia's Ge Force Now is coming to the Steam Machine later in 2026

Google just fixed one of the most annoying things about talking to AI

Meta thought AI could do the job instead of humans — what happened next should surprise absolutely nobody

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.