Researchers from the Georgia Institute of Technology have uncovered significant security flaws in Tile's popular Bluetooth location trackers, raising concerns about user privacy and the potential for malicious tracking. The investigation revealed that each Tile device broadcasts an unencrypted, static MAC address along with a unique identifier, making it possible for any nearby Bluetooth-enabled device or radio-frequency antenna to intercept these signals. Unlike competing trackers that use temporary, rotating IDs to obscure the device's identity, Tile's approach leaves the MAC address unchanged, which allows for persistent tracking of the device and, by extension, its owner. The researchers also found that while Tile does rotate its unique ID, the method used is weak and can be easily circumvented, enabling continuous monitoring. Data collected by nearby devices is sent to Life360's servers without encryption, and the researchers believe this information may be stored in cleartext, further compounding privacy risks. This design flaw means that an attacker only needs to capture a single broadcast from a Tile device to fingerprint and track it indefinitely. The scale of the issue is significant, with approximately 88 million Tile trackers in use worldwide, amplifying the potential impact. The vulnerabilities are not mitigated by the safeguards Tile introduced in 2023, which were intended to prevent misuse by owners but do not address third-party tracking via Bluetooth sniffers. Such sniffers are widely available and commonly used in retail environments and smart-home setups, making the exploitation of these flaws trivial for both individuals and organizations. The researchers warn that these weaknesses could be exploited by stalkers, thieves, or other malicious actors to follow individuals without their knowledge. The lack of encryption in both the device broadcasts and the communication with Life360's infrastructure means that sensitive location data could be intercepted or misused in the event of a breach. The findings highlight a broader issue in the rapidly growing Bluetooth tracker market, where security and privacy considerations have not kept pace with adoption. The researchers emphasize that the current implementation allows for mass surveillance if Tile trackers are caught in large-scale scans. They also note that other tracker systems use more robust encryption and key management to protect user privacy, underscoring Tile's lag in adopting industry best practices. The exposure of static MAC addresses and weak ID rotation not only facilitates stalking but also opens the door to broader privacy violations and potential data breaches. The researchers' warnings serve as a call to action for both manufacturers and users to prioritize security in the design and use of location-tracking devices. Life360, the parent company of Tile, has not yet announced any immediate remediation steps in response to these findings. The incident underscores the importance of rigorous security assessments for consumer IoT devices, especially those with the potential to impact personal safety and privacy on a large scale.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The Georgia Tech researchers said attackers could replay Tile Bluetooth broadcasts to make it appear that a legitimate Tile owner was conducting stalking activity. This added a new abuse scenario beyond covert tracking, showing the flaws could also be used to falsely implicate users.
The researchers said the design flaws undermine Tile's 2023 anti-misuse protections because they enable covert tracking of a tag's owner without planting a separate tracker. They recommended encrypting Bluetooth broadcasts and server communications to reduce stalking risk and limit misuse of historical location data.
Researchers at the Georgia Institute of Technology found that Tile Bluetooth trackers broadcast an unencrypted MAC address and unique identifier, allowing nearby Bluetooth devices or RF antennas to track a tag's movements. They also reported that tag location, MAC address, and unique ID are transmitted unencrypted to Tile's servers, potentially enabling tracking of a tag owner.
6 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcemalwarebytes.com
Open sourcearxiv.org
Open sourcetomshardware.com
Open sourcearchive.ph
Open sourceeprint.iacr.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.