Researcher enrolled a Linux device into Apple Find My to receive people-location data shared with an Apple account

A researcher showed that a Linux machine can be made to act like an Apple device in Find My and receive live location data that other people had already shared with the account owner. The method does not expose arbitrary users’ locations, but it abuses Apple’s legacy account and device-enrollment flows, including GrandSlam authentication, Apple Identity Services device certificates, and Apple Push Notification service registration, to add a non-Apple device and fetch shared people-location updates.
Why it matters: This is a meaningful privacy and trust-boundary issue for Apple users who rely on Find My sharing, because location data intended only for Apple hardware can be pulled to unsupported systems. Apple users should review who they share location with, and Apple should tighten device attestation and legacy enrollment paths.

Sources

Researcher tricks Apple’s Find My into sharing location data with Linux
2026.08.20 100% relevant
This article appears to be the first report here describing the specific protocol technique for enrolling Linux into Apple’s Find My network to retrieve already-shared people-location data, establishing a distinct Apple privacy/security story.
← Back to all stories