Back to Paper
cs.CRcs.CY
Local ID: 2604.10138v2
AI Summary: gemma4:e4b
A Relay a Day Keeps the AirTag Away: Practical Relay Attacks on Apple's AirTags
By Gabriel K. Gegenhuber, Leonid Liadveikin, Florian Holzbauer, Sebastian Strobl
Revision History Timeline
v14/11/2026
4/11/2026
“Presented at ACSAC 2025”
v24/14/2026
4/14/2026
“Poster presented at ACSAC 2025. Relay experiments were originally conducted in 2022 by Sebastian Strobl (bachelor thesis) and subsequently repeated and reproduced in 2025 by Leonid Liadveikin (university project)”
★ Version indexed in ExplorerComparing v1 vs v2
Green = Added • Red = Removed
Title Comparison
A Relay a Day Keeps the AirTag Away: Practical Relay Attacks on Apple's AirTags
Authors Comparison
No author changes.
v1 Comment
“Presented at ACSAC 2025”
v2 Comment
“Poster presented at ACSAC 2025. Relay experiments were originally conducted in 2022 by Sebastian Strobl (bachelor thesis) and subsequently repeated and reproduced in 2025 by Leonid Liadveikin (university project)”
Abstract Word Diff
Apple AirTags use Apple's Find My network: when nearby iDevices detect a lost tag, they anonymously forward an encrypted location report to Apple, which the tag's owner can then fetch to locate the item. That encryption protects privacy -- neither the finder nor Apple learns the owner's identity -- but it also prevents Apple from validating the correctness of received reports. We show that this design weakness can be exploited: using a relay attack, we can inject manipulated location reports so the Find My service reports a false position for a lost AirTag. The same technique can be used to deny recovery of a targeted tag (a focused DoS), since the owner is misled about its whereabouts.