The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may result in unauthorized removal of devices associated with the account.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Apple Find My Backend Authentication Bypass Allows Device Enumeration and Removal |
Wed, 29 Jul 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Apple Find My Backend: Unauthorized Device Removal via Private Endpoint Token |
Sun, 26 Jul 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Apple Find My Backend: Unauthorized Device Removal via Private Endpoint Token |
Wed, 22 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 CWE-306 |
|
| Metrics |
cvssV3_1
|
Tue, 21 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may result in unauthorized removal of devices associated with the account. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-07-21T00:00:00.000Z
Updated: 2026-07-22T15:46:53.127Z
Reserved: 2025-12-20T00:00:00.000Z
Link: CVE-2025-68640
Updated: 2026-07-22T15:16:37.307Z
No data.
No data.