Apple’s Find My Network Could Be Exploited to Send Text Messages to Nearby Devices, Security Researcher Finds

Security researcher Fabian Bräunlein has found a loophole in Apple’s Find My network protocol that could be exploited.

Advertisement
By Jagmeet Singh | Updated: 13 May 2021 13:41 IST
Highlights
  • Apple’s Find My network could be manipulated to send text messages
  • Find My network normally shares GPS coordinates from devices
  • The researcher faked the way AirTag communicates
Apple’s Find My Network Could Be Exploited to Send Text Messages to Nearby Devices, Security Researcher Finds

Apple has designed Find My network to allow users to find their lost items

Photo Credit: Apple

Apple's Find My network could be exploited to broadcast arbitrary messages to nearby Apple devices, a security researcher has found. The network is formally meant to help people find their lost items. It is claimed to have “industry leading security” as well as end-to-end encryption. However, research shows that the Find My network can enable a way to send any text messages — and not location details — to nearby devices including iPhone, iPad, and Mac.

Security researcher Fabian Bräunlein has found a loophole that allows exploitation of the Find My network protocol to send normal text messages to nearby devices. The researcher was able to transmit text messages by replicating the way an AirTag communicates over the crowdsourced network and sends its GPS coordinates as an encrypted message.

Bräunlein took reference from a recent study conducted by Germany's Technical University (TU) of Darmstadt that was aimed to help developers build accessories for the Find My network. After understanding the protocol powering the network, the researcher developed a custom device with a microcontroller running a proprietary firmware to transmit the message. He also built a custom Mac app to decode and display the message from the device.

The proof-of-concept created by Bräunlein essentially replaces the location data that the Find My network normally broadcasts with text strings.

Advertisement

It is unclear at this moment whether the model developed by the researcher could be used to circulate malicious content over the Find My network. However, the extensive research conducted by Bräunlein shows that the protocol used by Apple could be moulded to broadcast not location data but content such as text messages.

Earlier this week, a German security researcher reported that the Apple AirTag could be hacked to replace the default Find My link with a custom link for NFC readers. This manipulation was similar in nature to what has now been found on the Find My network.


We dive into all things Apple — iPad Pro, iMac, Apple TV 4K, and AirTag — this week on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple's M4 Mac Mini Price in India Drops to Rs. 49,999 With These Discounts
  2. Poco F7 Design Spotted in Leaked Renders; Battery Specifications Revealed
  3. Here's When Samsung Might Launch the Galaxy Z Fold 7 and Z Flip 7
  4. OnePlus Pad Lite Design and Specifications Leaked, Could Launch Soon
  1. OnePlus Pad Lite Design and Key Specifications Leaked, Could Launch Soon
  2. Samsung's Upcoming Running Events Reportedly Hint at Galaxy Z Fold 7, Flip 7 and Watch 8 Series Launch Timeline
  3. Poco F7 Design Spotted in Leaked Renders; Battery Specifications Revealed via Flipkart
  4. Neuralink Device Helps Monkey See Something That’s Not There
  5. Apple's Mac Mini With M4 Chip Price in India Drops to Rs. 49,999 With Discounts on Amazon
  6. Samsung Galaxy M36, Galaxy F36 Spotted on Google Play Console; Galaxy M36 Launch Reportedly Teased via Amazon
  7. Google, Scale AI's Largest Customer, Said to Plan Split After Meta Deal
  8. SpaceX Launches 26 New Starlink Satellites, Expands Global Internet Network
  9. Aurora Alert! Northern Lights May Be Visible as Far South as New York on June 14
  10. New Island Forms in Caspian Sea as Water Levels Drop, Russian Scientists Confirm
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.