A bug appearing for a small number users on iCloud.com may allow them to temporarily track and make changes to Macs belonging to other users, according to reports appearing on Twitter. Users have noted that Macs with names they don’t recognize recently started appearing in the device list on the Find My iPhone web service, allowing them to remotely lock or erase the computers in some cases, or just play a sound in others.
Update: The exact nature of the problem is difficult to pin down, but a person aware of the issue says that this is likely related to users not properly erasing their Macs before transferring them to someone else. Sources have told us that following the steps on this Apple help document should fix it. That said, we’re still investigating since some users don’t seem to fall into that category, and have reached out to Apple for more information.
Some users also speculate that perhaps these are used Macs that were sold to someone else and are now pinging the wrong iCloud account. It’s certainly a possibility that this could be the source of the confusion, since Find My Mac configuration is saved on a computer even after the operating system has been reinstalled.
That theory doesn’t seem to always hold up in this case, however, since some users seeing the problem claim to have never sold their Mac to a friend.
Manuello in Portland, are you out there? I seem to have been given control of your iMac. pic.twitter.com/MiAySZtzDC— Robb Shecter (@dogweather) May 14, 2015
Who is Jary and why is his Mac appearing in Find My iPhone? pic.twitter.com/b2nKHndQEw— Robin Senior (@senior) May 14, 2015
Find my iPhone on http://t.co/PMlZlDR8kT shows me a MacBook named "Triple" that is not mine. Not reassuring. (I can only "Play Sound" in it)— John Siracusa (@siracusa) May 14, 2015
@siracusa maybe an old one you sold to someone? I had a Mac Pro that I definitely wiped but continued to ping its location to me.— 𝙼𝚊𝚞 𝚂 (@holaMau) May 14, 2015
@siracusa I have no weirdly-named devices, but do have some I KNOW I deactivated before selling…— Jason Petersen (@jasonmp85) May 14, 2015
@cabel Never, but it could be an old Apple loaner or something.— John Siracusa (@siracusa) May 14, 2015
At least one user reports knowing the person whose Mac showed up on his account, so the glitch may not be entirely random. Other affected machines could be used computers or loaners (as suggested by John Siracusa above) that simply didn’t get wiped from the user’s iCloud account properly.
@siracusa I'm also seeing a friend's computer listed. This is unbelievably bad.— Jason Becker (@jsonbecker) May 14, 2015
Several of us here at 9to5Mac have checked our own accounts and found nothing out of the ordinary. It seems likely that this is simply a case of machines that were previously linked to an iCloud account showing up again in error, and not necessarily a widespread issue allowing anyone to hijack a random stranger’s Mac.
One of the users reporting the issue above also postulates that this bug could be connected to him being in the area shown on the map yesterday, though this solution seems unlikely. In any case, if you happen to spot a strange Mac listed on your iCloud account, the best thing to do is simply leave it alone.
Some users may recall that Apple’s iTunes Connect portal suffered from a similar problem earlier this year when developers started seeing apps and login names belonging to different developers. In another case, emails sent to iCloud address were delivered to the wrong users.