paper

A Relay a Day Keeps the AirTag Away: Practical Relay Attacks on Apple's AirTags

arXiv:2604.10138

Abstract

Apple AirTags use Apple's Find My network: when nearby iDevices detect a lost tag, they anonymously forward an encrypted location report to Apple, which the tag's owner can then fetch to locate the item. That encryption protects privacy -- neither the finder nor Apple learns the owner's identity -- but it also prevents Apple from validating the correctness of received reports. We show that this design weakness can be exploited: using a relay attack, we can inject manipulated location reports so the Find My service reports a false position for a lost AirTag. The same technique can be used to deny recovery of a targeted tag (a focused DoS), since the owner is misled about its whereabouts.

Poster presented at ACSAC 2025. Relay experiments were originally conducted in 2022 by Sebastian Strobl (bachelor thesis) and subsequently repeated and reproduced in 2025 by Leonid Liadveikin (university project)