Apple AirTag has been launched less than two weeks ago, but a security researcher already claims to have hacked them.
The Apple AirTag has been available for just a couple of weeks and hacking community is already working on it to demonstrate that how to compromise it.
“The German security researcher Stack Smashing tweeted today (via The 8-bit) that he was able to “break into the microcontroller of the AirTag” and modified elements of the item tracker software.” reported the 9to5Mac website.
“A microcontroller is an integrated circuit (IC) used for controlling devices usually via a microprocessing unit, memory, and other peripherals. According to AllAboutCircuits, “these devices are optimized for embedded applications that require both processing functionality and agile, responsive interaction with digital, analog, or electromechanical components.”
Now, the German security researcher Stack Smashing claims that he was able to hack the Apple device breaking into its microcontroller and modifying its NFC URL for Lost Mode.
The researcher explained that has found a way to modify the tracker software running on the tag, he was able to modify its NFC URL.
Smashing published a video PoC of the hack, it shows two Apple AirTag devices and one of them was hacked by the researcher.
The regular item tracker used in the test opens the Find My website, while the modified one opens an arbitrary URL that was chosen by the expert.
Yesss!!! After hours of trying (and bricking 2 AirTags) I managed to break into the microcontroller of the AirTag! /cc @colinoflynn @LennertWo pic.twitter.com/zGALc2S2Ph— stacksmashing (@ghidraninja) May 8, 2021
Built a quick demo: AirTag with modified NFC URL (Cables only used for power) pic.twitter.com/DrMIK49Tu0— stacksmashing (@ghidraninja) May 8, 2021Experts pointed out that this is possible because Apple lack in implementing a server-side blocking mechanism to prevent that a modified AirTag will access the Find My Network.
The post Researcher hacked Apple AirTag two weeks after its launch appeared first on Security Affairs.