AirTag 'Lost Mode' Vulnerability Can Redirect Users to Malicious Websites

The AirTag feature that allows anyone with a smartphone to scan a lost AirTag to locate the contact information of the owner can be abused for phishing scams, according to a new report shared by KrebsOnSecurity.

f1618938547
When an AirTag is set in Lost Mode, it generates a URL for https://found.apple.com and it lets the AirTag owner enter a contact phone number or email address. Anyone who scans that AirTag is then directed automatically to the URL with the owner's contact information, with no login or personal information required to view the provided contact details.

According to KrebsOnSecurity, Lost Mode does not prevent users from injecting arbitrary computer code into the phone number field, so a person who scans an AirTag can be redirected to a phony iCloud login page or another malicious site. Someone who does not know that no personal information is required to view an AirTag's information could then be tricked into providing their ‌iCloud‌ login or other personal details, or the redirect could attempt to download malicious software.

The AirTag flaw was found by security consultant Bobby Raunch, who told KrebsOnSecurity that the vulnerability makes AirTags dangerous. "I can't remember another instance where these sort of small consumer-grade tracking devices at a low-cost like this could be weaponized," he said.

Rauch contacted Apple on June 20, and Apple took several months to investigate. Apple told Rauch last Thursday that it would address the weakness in an upcoming update, and asked him not to talk about it in public.

Apple did not answer his questions about whether he would receive credit or whether he qualified for the bug bounty program, so he decided to share details on the vulnerability because of Apple's lack of communication.

"I told them, 'I'm willing to work with you if you can provide some details of when you plan on remediating this, and whether there would be any recognition or bug bounty payout'," Rauch said, noting that he told Apple he planned to publish his findings within 90 days of notifying them. "Their response was basically, 'We'd appreciate it if you didn't leak this.'"

Last week, security researcher Denis Tokarev made several zero-day iOS vulnerabilities public after Apple ignored his reports and failed to fix the issues for several months. Apple has since apologized, but the company is continuing to receive criticism for its bug bounty program and the slowness with which it responds to reports.

Related Forum: AirTags

Top Rated Comments

btrach144 Avatar
9 weeks ago
Why is apple so lazy and incompetent when dealing with security researchers?
Score: 45 Votes (Like | Disagree)
funandblindness Avatar
9 weeks ago

Why is apple so lazy and incompetent when dealing with security researchers?
Arrogance
Score: 32 Votes (Like | Disagree)
Naraxus Avatar
9 weeks ago
Rofl. And Apple has the chutzpah to claim they care about & protect user privacy
Score: 26 Votes (Like | Disagree)
Altivec88 Avatar
9 weeks ago
Its just sad what Apple has become. Here you have people finding vulnerabilities that the staff you pay didn't find. It's essentially like having other people on your payroll that you only have to pay if they find something. Instead they treat them like crap, ignoring simple credit, trying to hush them, or worse yet just ignoring the vulnerability. Its not like paying them would even be a blip in the billions/quarterly profit they make. Instead of encouraging people to report these thing to them, they push them away to potentially sell it to the bad guys. Hopefully it's worth the bad PR, unknown security holes, and the continued erosion of their "privacy" marketing BS.
Score: 25 Votes (Like | Disagree)
SpaceN64 Avatar
9 weeks ago
Well that sounds bad
Score: 15 Votes (Like | Disagree)
red elma Avatar
9 weeks ago
Vulnerability chances are greater in logging into this forum than an AirTag in 'Lost Mode'
Score: 15 Votes (Like | Disagree)

Related Stories

f1618938547

Police Find Unexpected Use for Apple AirTags

Monday July 19, 2021 3:15 am PDT by
The utility of Apple's AirTag item trackers have started to be seen in law enforcement when locating stolen property, according to recent reports. As reported by GadgetLite, an AirTag user in Boston was able to recover their stolen property with the help of the police and Apple's small tracking device. Earlier this month, the user discovered that his bike had been stolen. Thankfully, he...
apple unknown items scan

iOS 15.2 Adds Option to Scan for Nearby AirTags and Find My-Enabled Items

Tuesday November 9, 2021 11:41 am PST by
With the iOS 15.2 beta that was released today, Apple has added enhancements to the Find My app. There's a new feature that's designed to let users scan for AirTags or Find My-enabled items that might be tracking them. When opening the Find My app after installing the beta and going to the "Items" tab, there's an option for "Items That Can Track Me." Tapping on this allows users to search...
airtag 1

AirTag Anti-Stalking Measures 'Just Aren't Sufficient' Says Washington Post Report

Wednesday May 5, 2021 6:03 pm PDT by
The safeguards that Apple built into AirTags to prevent them from being used to track someone "just aren't sufficient," The Washington Post's Geoffrey Fowler said today in a report investigating how AirTags can be used for covert stalking. Fowler planted an AirTag on himself and teamed up with a colleague to be pretend stalked, and he came to the conclusion that the AirTags are a "new means...
airtag in hand

Apple Enhancing AirTags Anti-Stalking Measures With Android App and Shorter Sound Intervals

Thursday June 3, 2021 11:10 am PDT by
Apple is enhancing AirTags security to prevent stalking using the Bluetooth devices, Apple told CNET today. Apple is already sending out over-the-air updates to AirTags that will shorten the amount of time before an unknown AirTag alerts you if it is in your possession. At the current time, AirTags play a sound after three days of being away from their owner. After the update, AirTags will...
airtag notification

Lost AirTags Can Be Read By NFC-Enabled iPhones and Android Devices

Wednesday April 21, 2021 12:43 am PDT by
Apple's AirTag tracking devices can be identified by Android phones when they're in Lost Mode, according to a new support document published by Apple. Announced on Tuesday, Apple's new AirTag item trackers let you easily track things like your keys, wallet, purse, backpack, luggage, and more. They work using an ultra-wideband U1 chip to keep in touch with the Find My network. However,...
maxresdefault

Hands-On With Apple's New AirTags

Friday April 30, 2021 2:41 pm PDT by
After years of waiting for the AirTags to debut, launch day is finally upon us and AirTags are now in the hands of customers. We got our AirTags in the mail today and thought we'd share a hands-on look for those who are still waiting for their orders or debating whether AirTags might be useful. Subscribe to the MacRumors YouTube channel for more videos. As you probably know by now, AirTags...
f1618938547

Apple Executive Says AirTags Designed to Track Items, Not Children or Pets

Thursday April 22, 2021 6:42 am PDT by
Following the announcement of AirTags this week, Apple's VP of worldwide iPhone product marketing, Kaiann Drance, and Apple's senior director of sensing and connectivity, Ron Huang, spoke with Fast Company about the Tile-like tracker and its design and privacy. Speaking about the design of AirTag, Drance says Apple wanted to create a simple yet unique design for the tracker, keeping in mind...
AitTag New Firmware

Apple Makes Latest AirTags Firmware Available to All Users

Wednesday September 15, 2021 9:56 am PDT by
Apple this week continued distributing new firmware for the AirTags that first rolled out in August. There have been several minor releases with different build numbers, and behind the scenes, those tweaks were to meter the number of people who were seeing the AirTag update at one time. The last version, for example, with a build number of 1A291e changed nothing other than the rate limit on...

Popular Stories

Mac Notebook Upgrade Program

Apple Introduces New MacBook Upgrade Program for Business Partners

Monday November 29, 2021 7:38 am PST by
In association with CIT as the financing partner, Apple has launched a new Mac Upgrade Program for small businesses and Apple business partners that allow companies to easily distribute and upgrade their fleets of MacBooks at an affordable price to all of their workers. As outlined on CIT's website, shared by Max Weinbach, Apple Business Partners can distribute the 13-inch MacBook Pro,...
General cyber monday 20 sale feature

Best Cyber Monday Deals for AirPods, Apple Pencil, iMac, More

Monday November 29, 2021 4:19 am PST by
With Black Friday over, Cyber Monday 2021 is now in full swing and you can find many of the same sales as last week on Apple products like AirPods, Apple Pencil, and iPad Pro. In this article we're focusing on the best Cyber Monday discounts on Apple products like these and more. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we...
2017 apple tv

Cyber Monday: Original Apple TV 4K Drops to $99.99 for Amazon Prime Members

Monday November 29, 2021 12:01 pm PST by
We've been tracking Apple product and accessory deals for Cyber Monday 2021 today, and now Woot is offering a solid discount on the previous generation 32GB Apple TV 4K. You can get this device in new condition for just $99.99 if you're an Amazon Prime member. Note that this sale will last for one day only. Note: MacRumors is an affiliate partner with some of these vendors. When you click a...
iPhone SE Cosmopolitan Clean

New iPhone SE Reportedly on Track for Release in First Quarter of 2022

Tuesday November 30, 2021 8:08 am PST by
Apple plans to release a third-generation iPhone SE in the first quarter of 2022, according to Taiwanese research firm TrendForce. If this timeframe proves to be accurate, we can expect the device to be released by the end of March. As previously rumored, TrendForce said the new iPhone SE will remain a mid-range smartphone with added support for 5G:In terms of product development, Apple is...
maxresdefault

Five Features to Look Forward to in the 2022 MacBook Air

Tuesday November 30, 2021 1:51 pm PST by
In 2022, Apple is going to release an updated version of the MacBook Air with some of the biggest design changes that we've seen since 2010, when Apple introduced the 11 and 13-inch size options. In the video below, we highlight five features that you need to know about the new machine. Subscribe to the MacRumors YouTube channel for more videos. No More Wedge Design - Current MacBook...
telsa cyberwhistle

Elon Musk Urges Customers to Buy 'Tesla Cyberwhistle' Instead of Apple Polishing Cloth

Wednesday December 1, 2021 4:01 am PST by
Tesla CEO Elon Musk has encouraged customers to buy the "Cyberwhistle" for $50 instead of Apple's much-discussed Polishing Cloth. The product page, which Musk shared on Twitter on Tuesday evening, offers a limited edition stainless steel whistle with the same distinctive design of the Tesla Cybertruck:Inspired by Cybertruck, the limited-edition Cyberwhistle is a premium collectible made from ...
General cyber monday 20 sale feature 2

Best Cyber Monday Apple Accessory Deals Available Today

Monday November 29, 2021 6:41 am PST by
We started sharing deals on Apple products for Cyber Monday 2021 earlier today, and now we're tracking deals and bargains available from all of the best Apple accessory companies. Similar to Black Friday, you can expect Cyber Monday savings from Twelve South, Nomad, Belkin, Casetify, and many more. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and...
iphone holiday

Best Black Friday iPhone Deals Still Available

Friday November 26, 2021 4:58 am PST by
Cellular carriers have always offered big savings on the newest iPhone models during the holidays, and Black Friday 2021 sales have now carried over into Cyber Monday as well. Right now we're tracking notable offers on the iPhone 13 and iPhone 13 Pro devices from AT&T, Verizon, and T-Mobile. For even more savings, keep an eye on older models like iPhone SE. Note: MacRumors is an affiliate...
airpods prototype translucent

Transparent AirPods and 29W Power Adapter Prototypes Surface in Photos

Tuesday November 30, 2021 7:16 am PST by
Images of transparent prototype AirPods and a 29W Apple power adapter have been shared on Twitter by Apple device collector Giulio Zompetti. The prototypes, which appear to be either first-generation or second-generation AirPods, feature clear plastic along the stem and around the outer side of the earbud, with the normal white plastic on the inner side of the earbud. Transparent casings are ...