Skip to content
Breaking:

Security Researcher Connects Linux Machine to Apple's Restricted Find My Location Network

By impersonating native Apple hardware, a custom Linux client successfully received real-time location data through Apple's proprietary infrastructure.

By The Company Wire3 min read
Share
Apple — Security Researcher Connects Linux Machine to Apple's Restricted Find My Location Network
Apple — Security Researcher Connects Linux Machine to Apple's Restricted Find My Location Network. Photo: TechRadar Pro.

A security researcher has successfully registered a standard Linux computer as a trusted node on Apple's proprietary Find My network, enabling the non-Apple system to receive real-time location data shared by other users.

The research, conducted by a 22-year-old security researcher known online as "Zerotistic" and first reported by TechRadar Pro, demonstrates that Apple’s strict ecosystem boundary around location sharing relies largely on obscure network protocols rather than hardware-level cryptographic barriers.

Apple's Find My ecosystem allows users to track hardware such as iPhones, iPads, and AirTags, while also enabling individuals to share their personal whereabouts with approved contacts. Historically, Apple has restricted access to these live location streams exclusively to its own operating systems and device family.

To access the system, the researcher constructed a custom Linux client capable of replicating the specialized network communications required by Apple’s back-end infrastructure. Apple distributes location updates through its private Apple Push Notification service (APNs) only after validating that a requesting machine belongs to a recognized account and possesses valid system credentials.

Establishing trust required generating an Apple Identity Services (IDS) certificate—an internal credential frame Apple uses to bind account credentials to specific hardware—alongside encryption keys and APNs tokens. By submitting a certificate signing request to a legacy Apple device enrollment endpoint, the researcher obtained valid authorization for the Linux machine.

Once certified, the Linux setup signed its own requests and registered as a valid Find My device after subscribing to six required subservices. The researcher then issued a "SubscribeAndFetch" request containing an encrypted location key supplied by a friend's iPhone, prompting Apple's servers to stream real-time position data directly to the Linux machine.

The entire setup was constructed within a week without utilizing jailbroken devices, leaked private keys, or physical Mac hardware. Instead, the pipeline was created using open-source utilities, decompiled Apple daemons, and standard trial-and-error testing.

The technique cannot be used to track strangers without authorization, as it still requires an explicit location-sharing opt-in from the target user. However, the experiment demonstrates that Apple's back-end servers treat non-Apple hardware as trusted nodes once the machine mimics internal system handshakes. Apple has not publicly indicated whether it plans to update its enrollment endpoints to block similar software clients.

Sources

  1. TechRadar Pro

Company: Apple

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.