Gadgets

Vulnerability in Apple devices exposed user location


Another vulnerability identified in devices fromApple has allowed cybercriminals to track the movement of gadget owners over the past seven days. The issue was discovered by cyber security experts from the Secure Mobile Networking Lab at the Technical University of Darmstadt, Germany in the Find My feature, which is preinstalled on iPhone, iPad, iPod touch, Apple Watch, Mac or AirPods.

Find function for finding devicesMy broadcasts Bluetooth Low Energy (BLE) signals from Apple gadgets to nearby devices, which in turn transmit their location to Apple servers. Thus, each of the Apple devices turns into a broadcast beacon.

The technology uses public key encryption(public key encryption, PKE), which prevents even Apple specialists from locating users. However, using the relative location of the owners of various devices, reported by search devices, can be used by law enforcement agencies to "de-anonymize the participants in (political) demonstrations, even when the participants put their phones in flight mode," experts say.

Secure Mobile Networking Lab experts have identifiedthe problem last year and immediately reported it to Apple. Already in November 2020, in the macOS 10.15.7 build, the vulnerability was eliminated using "improved access restrictions".

Source: securitylab