• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Security researcher successfully jailbreaks an Apple AirTag

May 10, 2021
Share on FacebookShare on Twitter

  • After permanently bricking two AirTags, stacksmashing succeeded in breaking into and reprogramming a third.

  • stacksmashing used segger.com’s J-Link flash download utility to extract firmware from the AirTag’s nRF52 Bluetooth Low Energy SoC.

  • Here’s the loot—AirTag firmware files extracted from their nRF52 SoC, in .bin format.

This weekend, German security researcher stacksmashing declared success at breaking into, dumping, and reflashing the microcontroller of Apple’s new AirTag object-location product.

Breaking into the microcontroller essentially meant being able both to research how the devices function (by analyzing the dumped firmware) and to reprogram them to do unexpected things. Stacksmashing demonstrated this by reprogramming an AirTag to pass a non-Apple URL while in Lost Mode.

Lost Mode gets a little more lost

When an AirTag is set to Lost Mode, tapping any NFC-enabled smartphone to the tag brings up a notification with a link to found.apple.com. The link allows whoever found the lost object to contact its owner, hopefully resulting in the lost object finding its way home.

After breaching the microcontroller, stacksmashing was able to replace the found.apple.com URL with any other URL. In the demonstration above, the modified URL leads to stacksmashing.net. By itself, this is pretty innocuous—but it could lead to an additional minor avenue toward targeted malware attacks.

Tapping the AirTag won’t open the referenced website directly—the owner of the phone would need to see the notification, see the URL it leads to, and elect to open it anyway. An advanced attacker might still use this avenue to convince a specific high-value target to open a custom malware site—think of this as similar to the well-known “seed the parking lot with flash drives” technique used by penetration testers.

Advertisement

AirTag’s privacy problems just got worse

AirTags already have a significant privacy problem, even when running stock firmware. The devices report their location rapidly enough—thanks to using detection by any nearby iDevices, regardless of owner—to have significant potential as a stalker’s tool.

It’s not immediately clear how far hacking the firmware might change this threat landscape—but an attacker might, for instance, look for ways to disable the “foreign AirTag” notification to nearby iPhones.

When a standard AirTag travels near an iPhone it doesn’t belong to for several hours, that iPhone gets a notification about the nearby tag. This hopefully reduces the viability of AirTags as a stalking tool—at least if the target carries an iPhone. Android users don’t get any notifications if a foreign AirTag is traveling with them, regardless of the length of time.

After about three days, a lost AirTag will begin making audible noise—which would alert a stalking target to the presence of the tracking device. A stalker might modify the firmware of an AirTag to remain silent instead, extending the viability window of the hacked tag as a way to track a victim.

Now that the first AirTag has been “jailbroken,” it seems likely that Apple will respond with server-side efforts to block nonstandard AirTags from its network. Without access to Apple’s network, the utility of an AirTag—either for its intended purpose or as a tool for stalking an unwitting victim—would become essentially nil.

Listing image by stacksmashing

Next Post

Spotify is making it easier to share podcasts on Android

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Rebellions closes $400M pre-IPO round at a $2.34B valuation
  • Marathon Review – IGN | N4G
  • AI’s $258B investment boom raises urgent questions about ROI & real impact
  • XGIMI’s most powerful projectors just opened up for pre-order
  • Flipsnack’s Living Visuals signals the shift to immersive AI-driven content

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously