Hackers can use AirTags to steal your Apple account — what you need to know

AirTag
(Image credit: Apple)

Apple's AirTags make it easy to phish people and steal their Apple accounts, a security researcher says.

Bobby Rauch, a Boston-area cybersecurity consultant, said in a blog post today (Sept. 28) that Apple makes it too easy to sneak malicious code into the online messages that AirTag owners can leave for anyone who finds their lost tracking discs.

"I can't remember another instance where these sort of small consumer-grade tracking devices at a low cost like this could be weaponized," Rauch told independent security reporter Brian Krebs, who first reported this story.

Tom's Guide has reached out to Apple for comment, and we will update this story when we receive a reply.

How to avoid this kind of attack

To protect yourself from this sort of attack, be aware that you don't need to log into iCloud or your Apple account to report a found AirTag. 

You should also enable two-factor authentication to make logging into your Apple account difficult for an attacker who does not possess one of your Apple devices, even if that attacker has your Apple username and password.

If you think your Apple ID has been phished or otherwise stolen, change your Apple password right away. 

Injection without detection

In a series of YouTube clips posted on Medium, Rauch showed how he could use off-the-shelf software to inject an invisible script into the phone-number field that an AirTag owner fills in when reporting a lost AirTag to Apple.

An iPhone user who came across the lost AirTag would connect their iPhone to it wirelessly, which, in turn, would force the iPhone to open a page at found.apple.com specific to that lost device. 

Normally, that Found page would contain information about contacting the lost AirTag's rightful owner. But in this case, the hidden script would secretly redirect the victim's iPhone to a page that would look like a standard iCloud login page, but would really be a phishing page ready to steal the victim's Apple username and password.

"Since Airtags were recently released, most users would be unaware that accessing the https://found.apple.com page doesn't require authentication at all," Rauch wrote on Medium. "The https://found.apple.com link can also be used as a phishing link, and shared via a desktop/laptop, without the need for a mobile device to scan the Airtag."

Easy to fix, not so easy to overlook

Rauch told Krebs that he told Apple about this vulnerability in June, but that Apple sat on it for three months while the company investigated. After the three-month mark passed — generally regarded as long enough for a security researcher to wait before disclosing an unpatched flaw — Rauch reached out to Krebs. 

Krebs contacted Apple for comment, soon after which Apple emailed Rauch and asked him not to discuss the vulnerability in public. Rauch obviously declined, telling Krebs he never got a timeline about when the bug would be fixed, whether he'd be credited with finding it, or whether he'd get any kind of "bug bounty" at all.

Last week, another security researcher, fed up with waiting for Apple to patch the flaws he'd discovered, simply put exploits for those flaws online.

Rauch told Krebs that patching this issue involves simply banning certain characters from the Found page's entry fields. 

"It's a pretty easy thing to fix," Rauch said. "Having said that, I imagine they [Apple] probably want to also figure out how this was missed in the first place."

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
Find My iPhone
Apple Find My hack turns any Bluetooth device into a secret AirTag — what we know
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
iPhone 15 Pro Max shown in hand
iMessage under attack from scammers sending phishing messages — don’t fall for it
A hacker typing quickly on a keyboard
Hackers can steal your accounts, and all it takes is a double-click — don’t fall for this new form of clickjacking
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
Latest in Tech
Casetify Bounce Suitcase
I ditched my Away Carry-On for a bright red suitcase made by a phone case brand, and I was shocked by how much I liked it
Columbia Sportswear and Intuitive Machines partnership
Columbia Sportswear’s UV-blocking technology just landed on the moon, and I spoke to the materials scientist who designed it
iPhone 16e review.
What Tom’s Guide tested this week — the iPhone 16e is the most polarizing phone of the year
A split screen photo showing a coffee grinder on one side and a smart watch on the other
What Tom’s Guide tested this week: Sony, OnePlus, Corsair and more
A split screen image showing an instant camera on the left and a Dyson vacuum on the right
What Tom’s Guide tested this week: Expert reviews of Dyson, Insta360 and more
A composite of Soundcore Space One Pro headphones and Sony ZV-1F vlogging camera
What Tom’s Guide tested this week: 5 products that won our expert reviewers’ hearts
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYTimes Connections
NYT Connections today hints and answers — Monday, March 24 (#652)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know