Security researcher Zerotistic demonstrated that a Linux system could be enrolled into Apple’s Find My ecosystem and receive live location data intended for Apple devices. The method did not allow arbitrary tracking of Apple users; it exposed location information only for people who had already chosen to share their location with the Apple account used in the test. According to the reports, the researcher obtained Apple identity credentials, registered the Linux machine with Apple services, and convinced both Find My and Apple Push Notification service that the device was legitimate.
The enrollment reportedly abused Apple’s profile-registration workflow by submitting a custom PKCS#10 certificate signing request using a 2048-bit RSA key signed with SHA-1 to Apple’s authenticateDS endpoint, which then returned an IDS certificate. After subscribing the Linux device to the required Find My subservices and encryption settings, the researcher triggered delivery of an encrypted location key and used a Linux script to unwrap and decrypt location messages containing coordinates and timestamps. The full process reportedly took less than a week of experimentation, and Apple had not publicly responded to questions about the research at the time of publication.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A security researcher published technical details showing how Apple’s private Find My People workflow could be reproduced on Linux, including GrandSlam authentication, IDS delegate token use, alloy service enrollment, and retrieval of shared location keys via APNS. The report said this was not a vulnerability requiring a patch because it only exposed location data already voluntarily shared with the researcher’s account.
After reporting on the demonstration, The Register asked Apple whether it was aware of the research and whether it planned to address the issue. Apple did not immediately respond to those questions.
A security researcher known as Zerotistic demonstrated that a Linux device could be enrolled into Apple’s Find My ecosystem and receive live location data intended for Apple devices. The method only exposed location data for people who had already chosen to share their location with the associated Apple account, not arbitrary Apple users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.