Apple sells Find My to locate lost earbuds, but researchers proved the same network can secretly track anyone — and it still works against millions of unpatched iPhones. Apple says Beats data does not identify you, but researchers proved it contains a permanent ID linked to your name, email, and phone number — and turning off analytics does not stop collection.
What they claim: Find My marketed as safety feature: "Find your lost Beats" using 1.5B-device crowdsourced mesh network.
What we found: nRootTag (George Mason, USENIX 2025): manipulates Find My crypto keys to turn ANY BLE device into covert tracker. 90% success, 10-ft accuracy, remote with ~$5 GPU rental. Apple patched iOS 18.2 but works against unpatched iPhones near target.
What they claim: FCC filings BCGA2576/BCGA2577 certify Beats for Class 1 Bluetooth. Apple requested PERMANENT confidentiality on all schematics and technical descriptions.
What we found: CVE-2023-27964 (CVSS 6.5): BT auth bypass allows headphone hijacking via paired-device spoofing. Apple's FIRST-EVER security update for audio products (firmware 5B66, May 2023). Users cannot verify firmware, trigger updates, or audit H1 chip code. Permanent FCC confidentiality blocks independent audit.
What they claim: Firmware updates described as automatic and seamless: "delivered automatically while charging and in Bluetooth range."
What we found: CVE-2023-27964 patch (5B66, May 2023): no way to force install, no changelog, no hash verification. Android users report persistent failures. Apple Community shows users unable to confirm patch installed. No rollback. Zero external accountability.
What they claim: Apple Beats analytics page: "None of the collected information identifies you personally. Information will only be used by Apple to improve quality and performance."
What we found: Mysk Inc. (Nov 2022) proved analytics contain DSID (Directory Services ID) — permanent ID tied 1:1 to Apple ID (name, email, phone, DOB). Tommy Mysk: "Knowing the DSID is like knowing your name." Analytics sent regardless of opt-out. Class action Libman v. Apple survived dismissal Jan 2026.
What they claim: Beats app Play listing: "You can use the Beats app even without providing consent to any optional permissions." Bluetooth listed as only required permission.
What we found: On Android, Beats app requests Location. On iOS, no separate app needed — native Settings integration. iOS gets ATT framework, Privacy Report. Android users get app outside Apple's privacy framework. Same $199 hardware, different privacy depending on phone OS.
What they claim: Apple says users can "withdraw consent and disable Analytics altogether at any time by going to App Settings and selecting Don't Send."
What we found: Mysk research (Nov 2022, confirmed by Gizmodo/9to5Mac): toggling off "Share iPhone Analytics" had no effect on data transmission. Same DSID-linked telemetry sent regardless. Chrome and Edge both respect their opt-out toggles.
What they claim: Beats analytics: "If you have consented and granted Location Permission, approximate location may be sent to Apple."
What we found: Find My BLE relay operates at firmware level regardless of analytics consent. H1 chip beacon always active outside case. Location derivable from 1.5B-device mesh even without Beats app Location Permission.
What they claim: Beats analytics described as collecting "device software versions, rename occurrences, update success/fail rates" — purely operational.
What we found: Apple analytics infrastructure (Mysk, Nov 2022) collects real-time interaction logs, search queries, ad views, device fingerprints, DSID. Beats pipeline feeds same Apple infrastructure caught collecting identifiable data from App Store, Music, TV, Books, Stocks.