apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally
No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally
No Result
View All Result
apple patient
No Result
View All Result

"Lost Mode": AirTags enable phishing scams

by Milan
September 29, 2021
AirTag phishing vulnerability

Photo by Unsplash / Đức Trịnh

The AirTag feature, which allows any person with a smartphone to scan a lost AirTag to find the owner's contact information, can be abused for phishing scams, a new report has now revealed.

When an AirTag goes into Lost Mode is transferred, it generates a URL for https://found.apple.com and allows the AirTag owner to store a phone number or email address. Anyone who scans the AirTag using the NFC interface will then be automatically redirected to this URL with the owner's contact information, without the need for a login or personal data to view the contact details provided.

“Lost Mode”: Phone number field could be abused for phishing

According to KrebsOnSecurity prevented However, Lost Mode does not allow users to insert arbitrary code into the phone number field, so a person scanning an AirTag can be redirected to a fake iCloud login page or other malicious website. Someone who is unaware that no personal information is required to view an AirTag's information could then be tricked into providing their iCloud login credentials or other personal information. Alternatively, the redirection could also download or otherwise execute malicious software. This particular AirTag vulnerability was discovered by security consultant Bobby Raunch, who told KrebsOnSecurity that the vulnerability makes AirTags dangerous.

I can't think of any other case where these small, inexpensive consumer tracking devices could be used as a weapon.

Vulnerability: Apple asks for silence

According to his own statements, Rauch contacted Apple on June 20th. Interestingly, the company needed several months to investigate the case. Last Thursday, Apple informed Rauch that the vulnerability would be fixed in an upcoming update. In response, Apple asked him to keep quiet. Rauch then wanted to know whether he would receive a reward. Apple itself did not respond to his question as to why it decided to make the vulnerability public. KrebsOnSecurity quotes Rauch as follows:

I told them: I'm willing to work with you if you can tell me when you plan to fix the vulnerability and if there will be an acknowledgement or a bug bounty payout. He told Apple that he planned to publish his findings within 90 days of the report. The response was: "We would appreciate it if you didn't publish this.

Just last week, security researcher Denis Tokarev disclosed several zero-day vulnerabilities in iOS after Apple ignored his reports and did not fix the problems for several months. Apple has since apologized, but the company continues to be criticized for its bug bounty program and the slowness with which it responds to important reports like this one. (Photo by Unsplash / Đức Trịnh)

  • Nomad AirTag Leather Loop in the test – recommended?
Have you already visited our Amazon Storefront? There you'll find a hand-picked selection of various products for your iPhone and other devices – enjoy browsing !
This post contains affiliate links .
Add Apfelpatient to your Google News Feed. 
Was this article helpful?
YesNo
Tags: AirTags
Previous Post

Fiscal year 2021 Q4: Apple opens the books at the end of October

Next Post

macOS Monterey Beta reveals High Power Mode

Next Post
macOS Monterey Beta High Power Mode

macOS Monterey Beta reveals High Power Mode

Apple TV+ highlights August 2025

Apple TV+: These are the highlights for August 2025

August 1, 2025
Apple iPhone

Apple sells three billionth iPhone since 2007

August 1, 2025
Apple tariffs

Apple faces record tariff costs in Q4

July 31, 2025

About APFELPATIENT

Welcome to your ultimate source for everything Apple - from the latest hardware like iPhone, iPad, Apple Watch, Mac, AirTags, HomePods, AirPods to the groundbreaking Apple Vision Pro and high-quality accessories. Dive deep into the world of Apple software with the latest updates and features for iOS, iPadOS, tvOS, watchOS, macOS and visionOS. In addition to comprehensive tips and tricks, we offer you the hottest rumors, the latest news and much more to keep you up to date. Selected gaming topics also find their place with us, always with a focus on how they enrich the Apple experience. Your interest in Apple and related technology is served here with plenty of expert knowledge and passion.

Legal

  • Imprint – About APFEPATIENT
  • Cookie Settings
  • Privacy Policy
  • Terms of Use

service

  • Partner Program
  • Netiquette – About APPLEPATIENT

RSS Feed

Follow Apfelpatient:
Facebook Instagram YouTube threads
Apfelpatient Logo

© 2025 Apfelpatient. All rights reserved. | Sitemap

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally

© 2025 Apfelpatient. All rights reserved. | Page Directory