logo

How Apple Wi-Fi Positioning System can be abused to track people around the globe

ID: d7f9b216-0f07-5200-b679-b5559ae467d5

STIX ID: report--d7f9b216-0f07-5200-b679-b5559ae467d5

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2024-05-23

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Researchers at the University of Maryland demonstrated that Apple's Wi‑Fi Positioning System (WPS) design allows opportunistic return of up to several hundred nearby BSSIDs and, because the API is unauthenticated and unrate‑limited, they were able to compile ~490 million geolocated BSSIDs worldwide; this capability can be abused for mass surveillance, tracking of individuals, groups, and sensitive sites. The paper documents scenarios (e.g., tracking homes, military movements, travel routers, Starlink terminals), reports coordinated disclosure to vendors, and recommends mitigations including appending _nomap_ to SSIDs and implementing BSSID randomization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.