Tracking You from a Thousand Miles Away! Turning a Bluetooth Device into an Apple AirTag Without Root Privileges

Junming Chen, Xiaoyue Ma, Lannan Luo, Qiang Zeng

34th USENIX Security Symposium · Day 1

This groundbreaking research introduces **nRootTag**, a novel attack method that weaponizes Apple's ubiquitous Find My network to maliciously track Bluetooth-enabled devices, transforming them into de facto **AirTags** without requiring root privileges. Presented by researchers from George Mason University, this work exposes a critical vulnerability in the Find My implementation, demonstrating how ordinary computers and IoT devices running Linux, Windows, or Android can be co-opted for highly effective and stealthy location tracking. The implications for user privacy and security are substantial, given the global reach of Apple's Find My network, which encompasses over a billion active Apple devices acting as passive location reporters.

AI review

This is the real thing. A novel, practical attack that turns any Bluetooth device into an AirTag without root, backed by solid implementation work, real-world validation across a dozen platforms, and a cost model that makes it accessible to anyone with a few bucks and GPU rental access. Apple's going to have a bad quarter.