Device Enumeration Vulnerability in Apple Find My Service
CVE-2025-68640

Currently unrated

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2025-68640?

The Apple Find My backend service contains a vulnerability that enables an attacker with a valid Private Endpoint Token (PET) to manipulate device listings. This can lead to unauthorized enumeration of devices associated with an Apple ID and the potential to remove offline devices without requiring two-factor authentication or verifying ownership. Such exploitation poses significant risks to user accounts, allowing malicious actors to compromise device security and removal processes.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.