Apple’s ‘Find My’ Network Exploited via Bluetooth

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,159
Apple’s “Find My device” function for helping people track their iOS and macOS devices can be exploited to transfer data to and from random passing devices without using the internet, a security researcher has demonstrated.

Security researcher Fabian Bräunlein with Positive Security developed a proof of concept, using a microcontroller and a custom MacOS app, that can broadcast data from one device to another via Bluetooth Low Energy (BLE). Once connected to the internet, the receiving device can then forward the data to an attacker-controlled Apple iCloud server.

Bräunlein called the method “Send My,” and posited several use cases for the method — including the benign building of a network for internet-of-things (IoT) sensors, or as way to deplete people’s mobile-data plans over time.

The misuse of Find My in this way seems nearly impossible for Apple to prevent, he said, given that the capability is “inherent to the privacy and security-focused design of the Find My offline finding system,” Bräunlein observed.
Full technical details are available in the researcher’s blog post, published this week.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top