How a Modified AirTag Redirected Users to Scam Sites

Quick answer

A bug in Apple AirTags allowed a malicious actor to modify a tag so that when someone found it and scanned it, their iPhone would open a custom, potentially fraudulent, website instead of Apple's legitimate Find My page. Apple patched this vulnerability, limiting the type of information AirTags can display to only phone numbers or email addresses.

What was the AirTag 'Good Samaritan' bug?

The 'Good Samaritan' AirTag bug was a security vulnerability discovered by security researcher Fabian Braun. It exploited how AirTags allow an owner to input contact information that appears when someone finds a lost tag. Normally, this information directs the finder to a web page on Apple's Find My service, showing the owner's phone number or email address to facilitate its return.

The flaw involved entering a custom web address instead of a standard contact detail into the AirTag's designated field. Because the AirTag's system did not adequately validate the input, it would accept any URL. When an iPhone user tapped the notification from a found AirTag, their device would open this custom web address in their browser, potentially leading them to a malicious site.

How the scam worked for iPhone users

The attack began with a modified AirTag. Someone could program an AirTag to broadcast a phishing website address. A user finding this AirTag would receive an alert on their iPhone, indicating an unknown item detected nearby. When they followed the prompt to identify the item, their iPhone would display a notification with a link.

Tapping this link, which appeared to be part of the standard 'Found Item' process, would open the pre-programmed malicious website in their phone's browser. This site could impersonate a legitimate service, tricking the user into revealing personal data like Apple ID credentials, banking details, or other sensitive information. The victim would think they were helping to return a lost item, hence the 'Good Samaritan' name, but would instead fall into a trap.

Apple's response and the fix

Fabian Braun, the security researcher, reported this vulnerability to Apple. After the report, Apple released an update to address the issue. The fix restricts the type of data an AirTag can transmit for a found item. Owners can now only enter a phone number or an email address as contact information. It no longer accepts arbitrary web addresses.

This change ensures that when someone finds an AirTag and tries to return it, the link generated will always point to Apple's secure Find My web page displaying the contact information, or directly present the contact information to the user. It prevents any redirection to external, unverified websites. Apple has not publicly detailed the specific software version that included this patch, but the change has been observed in how AirTags function.

What this changes for AirTag users now

For most users, this fix strengthens the security of using AirTags to find lost items. The risk of encountering a malicious website via a found AirTag has been removed. You can continue to use AirTags for tracking personal belongings with greater assurance.

If you find an AirTag, the process for returning it remains largely the same. Your iPhone will still provide a notification, and you can tap it to see the owner's contact information. This information will now strictly be a phone number or email address displayed on Apple's trusted Find My site, rather than a potentially deceptive web link. This update also means that users attempting to modify AirTags for benign custom uses, like linking to a personal blog, can no longer do so through this mechanism.

Frequently asked questions

Is my AirTag still vulnerable to this type of attack?

No. Apple has implemented a fix that prevents AirTags from displaying custom web links, limiting them to only phone numbers or email addresses for contact information.

What should I do if I find an unknown AirTag?

If you find an unknown AirTag, you can still use your iPhone to identify it. The system will now only show the owner's phone number or email address on a secure Apple webpage, ensuring you are not redirected to a malicious site.

Did I need to update my AirTag firmware or iPhone software for this fix?

The fix was implemented by Apple on the backend, controlling what data an AirTag can store and broadcast for contact information. Users typically do not need to take specific action for this particular vulnerability, beyond keeping their iPhone software up to date.