Categories: News

PSA: AirTag bug can enable a ‘Good Samaritan’ attack

Apple’s US $30 AirTag tracking device has a feature that allows anyone who finds one of these tiny location beacons to scan it with a mobile phone and discover its owner’s phone number if the AirTag has been set to lost mode. However, KrebsonSecurity reports that this same feature can be abused to redirect the “Good Samaritan” to an iCloud phishing page — or to any other malicious website.

The vulnerability was discovered and reported to Apple by Bobby Rauch, a security consultant and penetration tester based in Boston. Rauch told KrebsOnSecurity the AirTag weakness makes the devices cheap and possibly very effective physical trojan horses.

Rauch said he realizes the AirTag bug he found probably isn’t the most pressing security or privacy issue Apple is grappling with at the moment. However, he said neither is it difficult to fix this particular flaw, which requires additional restrictions on data that AirTag users can enter into the Lost Mode’s phone number settings.

“It’s a pretty easy thing to fix,” he said. “Having said that, I imagine they probably want to also figure out how this was missed in the first place.”

KrebsOnSecurity says Apple hasn’t responded to requests for a comment.

Dennis Sellers

Dennis Sellers is the editor/publisher of Apple World Today. He’s been an “Apple journalist” since 1995 (starting with the first big Apple news site, MacCentral). He loves to read, run, play sports, and watch movies.

Recent Posts

Dr. Sumbul Desai, Apple’s vice president of Health, named to TIME’s list of the world’s most influential people in health

Dr. Sumbul Desai, vice president of Health at Apple, has been named to TIME magazine’s…

2 hours ago

FDA Qualifies Apple Atrial Fibrillation History Feature as an Medical Device Development Tool

The Apple Watch atrial fibrillation (AFib) history feature has been qualified by the FDA under…

2 hours ago

Google paid Apple $20 billion in 2022 to be Safari’s default search engine

Google’s Alphabet paid Apple US$20 billion in 2022 to be Safari’s default search engine according…

2 hours ago

KeyBudz’ HyperForm ear tips make your AirPods Pro even more comfortable

If your AirPods Pro aren’t as comfortable as you’d like, check out the HyperFoam ear…

4 hours ago

Why These WordPress LMS Options Are Rated the Best by Educators

Educators have searched for user-friendly Learning Management Systems (LMS) to improve teaching and learning.

4 hours ago

Today’s Deal: PDF Extra Personal Ultimate: Lifetime Subscription only $99.99

PDF Extra for Windows is an all-in-one solution featuring a streamlined workflow and a familiar…

4 hours ago