Device Enumeration Vulnerability in Apple Find My Service
CVE-2025-68640
Currently unrated
What is CVE-2025-68640?
The Apple Find My backend service contains a vulnerability that enables an attacker with a valid Private Endpoint Token (PET) to manipulate device listings. This can lead to unauthorized enumeration of devices associated with an Apple ID and the potential to remove offline devices without requiring two-factor authentication or verifying ownership. Such exploitation poses significant risks to user accounts, allowing malicious actors to compromise device security and removal processes.