CVE-2025-68640
Received Received - Intake

Apple Find My Backend Device Enumeration and Removal Vulnerability

Vulnerability report for CVE-2025-68640, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: MITRE

Description

The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may result in unauthorized removal of devices associated with the account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apple find_my *
apple find_my to 2025-12-17 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2025-68640 is a flaw in Apple's Find My backend service that lets an attacker with a valid Private Endpoint Token (PET) and Apple ID enumerate and remove devices from an iCloud account without triggering two-factor authentication or verifying device ownership. The attacker can list devices and remove offline ones silently, bypassing iCloud Lock protection.

Detection Guidance

Detection requires monitoring network traffic for unusual requests to Apple's Find My backend endpoints (/initClient, /authForUserDevice, /remove). Check logs for repeated failed authentication attempts or unauthorized device removal requests. Use network monitoring tools to inspect traffic to fmipmobile.icloud.com for suspicious PET token usage.

Impact Analysis

This vulnerability could allow an attacker to remove your devices from your iCloud account without your knowledge or consent. If your device is offline, the attacker can bypass Activation Lock and remove it, potentially gaining control over your device or preventing you from locating or using it.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling unauthorized access to and removal of devices linked to an Apple ID account. GDPR requires strict data protection and user control over personal data, while HIPAA mandates safeguards for protected health information. Unauthorized device removal may violate these standards by compromising data integrity and user access controls.

Mitigation Strategies

Enable multi-factor authentication (MFA) for your Apple ID. Review and revoke any suspicious sessions or devices linked to your account. Update your iOS devices to the latest version to ensure the patch is applied. Monitor account activity for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-68640. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart