apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
apple patient
No Result
View All Result

"Lost Mode": AirTags enable phishing scams

Milan Jovicic by Milan Jovicic
29. September 2021 - 14:24 CEST
in Apple News
0
AirTag phishing vulnerability

Photo by Unsplash / Đức Trịnh

WhatsAppFacebookEmail
Threads

The AirTag feature, which allows any person with a smartphone to scan a lost AirTag to find the owner's contact information, can be abused for phishing scams, a new report has now revealed.

When an AirTag goes into Lost Mode is transferred, it generates a URL for https://found.apple.com and allows the AirTag owner to store a phone number or email address. Anyone who scans the AirTag using the NFC interface will then be automatically redirected to this URL with the owner's contact information, without the need for a login or personal data to view the contact details provided.

“Lost Mode”: Phone number field could be abused for phishing

According to KrebsOnSecurity prevented However, Lost Mode does not allow users to insert arbitrary code into the phone number field, so a person scanning an AirTag can be redirected to a fake iCloud login page or other malicious website. Someone who is unaware that no personal information is required to view an AirTag's information could then be tricked into providing their iCloud login credentials or other personal information. Alternatively, the redirection could also download or otherwise execute malicious software. This particular AirTag vulnerability was discovered by security consultant Bobby Raunch, who told KrebsOnSecurity that the vulnerability makes AirTags dangerous.

I can't think of any other case where these small, inexpensive consumer tracking devices could be used as a weapon.

Vulnerability: Apple asks for silence

According to his own statements, Rauch contacted Apple on June 20th. Interestingly, the company needed several months to investigate the case. Last Thursday, Apple informed Rauch that the vulnerability would be fixed in an upcoming update. In response, Apple asked him to keep quiet. Rauch then wanted to know whether he would receive a reward. Apple itself did not respond to his question as to why it decided to make the vulnerability public. KrebsOnSecurity quotes Rauch as follows:

I told them: I'm willing to work with you if you can tell me when you plan to fix the vulnerability and if there will be an acknowledgement or a bug bounty payout. He told Apple that he planned to publish his findings within 90 days of the report. The response was: "We would appreciate it if you didn't publish this.

Just last week, security researcher Denis Tokarev disclosed several zero-day vulnerabilities in iOS after Apple ignored his reports and did not fix the problems for several months. Apple has since apologized, but the company continues to be criticized for its bug bounty program and the slowness with which it responds to important reports like this one. (Photo by Unsplash / Đức Trịnh)

  • Nomad AirTag Leather Loop in the test – recommended?
Make Apfelpatient a preferred source One click – and you'll see us more often on Google
Was this article helpful?
YesNo
Tags: AirTags
SendShareSend
Share

Our Amazon Storefront

A handpicked selection of products for iPhone, Mac and more – sorted by topic and updated regularly.

Shop Now

This post contains affiliate links (including Amazon). We earn a small commission on qualifying purchases – at no extra cost to you. Learn more on our Partner Program page.

Previous Post

Fiscal year 2021 Q4: Apple opens the books at the end of October

Next Post

macOS Monterey Beta reveals High Power Mode

Milan Jovicic

Milan Jovicic

Milan founded Apfelpatient in 2016 and has written all of its content himself since 2018 – news, rumors, guides and product reviews. Apple devices here aren't test units for a fortnight but everyday tools: from the iPhone to the MacBook Pro, MacBook Air and iMac through to the Apple Vision Pro, at least one device from nearly every product category is in daily use, many of them replaced annually. Every menu path in a guide is verified on the device before it goes live.

Six iPad Air models fanned out in different colors, one with its display on, as BOE aims to become a second panel supplier for the OLED iPad Air

iPad Air: BOE will supply the OLED display

August 11, 2026
Four current iPhone models side by side on a light background, while the code in iOS 27 already lists six unreleased iPhone models

iOS 27: Code reveals six unreleased iPhone models

August 11, 2026
Glass panel set into the aluminium frame on the back of an iPhone 17 Pro Max in Cosmic Orange, whereas the iPhone 20 glass design is said to wrap the glass around the edges

iPhone 20: Glass design is not supposed to be scrapped after all

August 11, 2026

About APFELPATIENT

APFELPATIENT brings you the latest Apple news, product updates, guides, reviews and tips across the entire Apple ecosystem — from the iPhone to the Mac to the Apple Vision Pro. From the first rumors to confirmed news: researched responsibly.

Follow Apfelpatient

Facebook Instagram YouTube Threads Threads

Company

  • About Apfelpatient
  • Contact
  • Author Profiles

Community

  • Netiquette
  • Push Notifications
  • RSS feed

Legal

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • Cookie Settings
  • Affiliate Program

Resources

  • Sitemap

© 2026 Apfelpatient. All rights reserved.

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights

© 2026 Apfelpatient. All rights reserved. Page Directory

Change language to Deutsch