Security researchers demonstrated that Apple’s Find My offline-finding network can be repurposed to transmit arbitrary data from devices without direct internet access by encoding message bits into crafted Bluetooth Low Energy broadcasts that nearby Apple devices forward to Apple’s backend. The proof of concept, dubbed Send My, used an ESP32 transmitter and a macOS retrieval tool derived from OpenHaystack to recover the data through authenticated queries to Apple’s location-report service, achieving roughly 3 bytes per second with end-to-end delays typically ranging from 1 to 60 minutes.
The work builds on reverse engineering behind OpenHaystack, an experimental framework for creating third-party Bluetooth accessories trackable through Apple’s Find My network. Researchers said the abuse is enabled by privacy-focused design choices that prevent Apple from linking broadcast public keys to owners, limiting authorization checks on report retrieval; they also noted prior security issues in the ecosystem, including CVE-2020-9986, which Apple fixed. The researchers proposed mitigations including BLE advertisement authentication and tighter rate limiting for location-report retrieval, while warning that experimental OpenHaystack firmware broadcasting a fixed public key can itself make accessories trackable by nearby devices.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
According to the OpenHaystack project documentation, Apple fixed CVE-2020-9986 after it was identified by the researchers. The flaw had allowed a malicious application to access location data.
Researchers at TU Darmstadt's Secure Mobile Networking Lab reverse engineered Apple's offline finding system and reported two vulnerabilities in it. One of the issues was CVE-2020-9986, which allowed a malicious application to access location data.
Positive Security disclosed a proof of concept showing Apple's Find My network could be abused to transmit arbitrary data by encoding it into crafted BLE messages relayed by nearby Apple devices. The write-up described an ESP32-based transmitter, a macOS retrieval application based on OpenHaystack, and argued the behavior stemmed from privacy-preserving design choices in Apple's system.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcepositive.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.