Junglewise Threat Intelligence

CVE-2025-68640: Apple Find My backend authorization bypass in device removal

CVE-2025-68640 · Severity: info · CVSS 0 · Published 2026-07-21

Vendors: Apple.

Executive brief

A vulnerability in Apple's Find My backend service allowed individuals with access to a specific account token to list and remove offline devices from an Apple ID. This process bypassed standard security measures like two-factor authentication and ownership verification. If exploited, an attacker could silently unlink a victim's device from their account, potentially disabling security features like Activation Lock.

Technical details

An improper authorization vulnerability existed in the Apple Find My (FMiP) backend (fmipmobile.icloud.com) due to improper token scoping. An attacker in possession of a valid Apple ID and its associated Private Endpoint Token (PET)—which could be obtained via session proxying or extraction—could interact with the /initClient, /authForUserDevice, and /remove endpoints. This allowed the attacker to enumerate all devices on an account and silently remove offline devices. The flaw is significant because it bypassed two-factor authentication (2FA) and trusted device verification workflows, effectively allowing the unauthorized removal of iCloud-locked devices and defeating Activation Lock protections. Apple reportedly patched this issue in July 2025.

Affected products

  • Apple Find My backend service through 2025-12-17

Timeline

  • 2025-05-02: disclosed: Reported to Apple Security Bounty program
  • 2025-07-13: patched: Apple addressed the vulnerability in the backend service
  • 2026-07-21: advisory: CVE-2025-68640 published to NVD

References