SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2025-68640

MEDIUM · CVSS 5.3 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The Apple Find My backend service is vulnerable, allowing attackers with a valid Private Endpoint Token to enumerate and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This could lead to unauthorized removal of devices, compromising account security. Organizations and users relying on Apple’s Find My service should prioritize addressing this vulnerability to protect their devices and accounts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-68640
Severity
MEDIUM
CVSS
5.3
EPSS
0.28%

Original NVD Description

The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may result in unauthorized removal of devices associated with the account.