Snatcher: Apple Find My Network Exposes Your Lost Devices To Strangers

June 19, 2026 ยท Grace Period ยท ๐Ÿ› the Proceedings of the 2026 ACM Conference on Computer and Communications Security

โณ Grace Period
This paper is less than 90 days old. We give authors time to release their code before passing judgment.
Authors Zhenyu Ren, Yanbo Zhang, Boya Liu, Mo Li arXiv ID 2606.21067 Category cs.CR: Cryptography & Security Citations 0 Venue the Proceedings of the 2026 ACM Conference on Computer and Communications Security
Abstract
Apple's Find My network connects nearly one billion devices to locate missing property via Bluetooth Low Energy (BLE). This paper reveals that insecure BLE advertisements and design tradeoffs allow unauthorized discovery and physical theft of lost Apple devices. We develop Snatcher, an attack and analysis framework implemented fully on Android smartphones without specialized hardware. Snatcher identifies vulnerabilities in unencrypted BLE advertisements, unauthenticated acoustic triggers, and slow MAC address randomization. Through three levels - sound-based direction finding, RSSI-IMU sensor-fusion navigation, and spatial-temporal clustering - our Android-based platform physically tracks and locates lost Apple accessories and devices in real-world tests. Our results highlight a crucial conflict between privacy protection, anti-stalking design, and physical security, urging Apple to strengthen Find My defenses.
Community shame:
Not yet rated
Community Contributions

Found the code? Know the venue? Think something is wrong? Let us know!

๐Ÿ“œ Similar Papers

In the same crypt โ€” Cryptography & Security