Apple’s latest gadget, the AirTag, has been hacked for the first time within two weeks of its launch in April 2021. A security researcher has been able to hack the accessory by modifying its NFC URL for Lost Mode.
The security researcher, Stack Smashing tweeted that he had been able to break into the microcontroller of the AirTag. Once he had broken in, he had modified elements of the item tracker software. This gives complete access to the hacker, and he can decide to do what he wants with it.
In the below video, we can see the difference in activity between a hacked AirTag and an un-hacked one. The regular AirTag opens the Find My website, whereas the hacked one opens a completely different URL. This can be used for phishing attacks.
The small circular AirTag can be attached to items like keys and wallets to allow these accessories to be tracked using Bluetooth right alongside Apple devices in the Find My app. The prices are modest compared to other Apple products. A single AirTag costs $29, and a pack of four cost $99.
The below video gives a detailed walkthrough of how the security researcher hacked the AirTag.
Till now, Apple has neither commented on this nor issued a fix for it.
Also Read
Hackers Threaten to Leak Stolen Blueprints of Apple products if $50 Million isn’t Paid
Zero-Click Flaw with Apple Mail Can be Triggered by Sending Two Zip Files
The U.S. Department of Justice unsealed federal charges Thursday against Russian national Rustam Rafailevich Gallyamov,…
A comprehensive security research demonstration has revealed how attackers can systematically undermine modern zero-trust security…
A cybersecurity threat has emerged targeting one of the world's largest fast-food chains, as a…
The cybersecurity landscape witnessed a significant milestone this February with the emergence of BypassERWDirectSyscallShellcodeLoader, a…
Cybercriminals are increasingly targeting cryptocurrency users through sophisticated malware campaigns that exploit the trust placed…
Cybersecurity researchers have uncovered a sophisticated new formjacking malware campaign targeting WooCommerce-powered e-commerce websites, representing…