Securing the invisible thread: a comprehensive analysis of BLE tracker security in Apple airtags and Samsung smarttags
摘要
This paper investigates the security of Bluetooth Low Energy (BLE) trackers, with a focus on Apple AirTags and Samsung Galaxy SmartTags. Our analysis covers hardware, firmware, radio signals, companion apps, and cloud services, highlighting weaknesses such as spoofing, firmware tampering, jamming, and location forgery. We show how Apple’s emphasis on user privacy creates authentication gaps, while Samsung’s cloud-centered model raises data exposure risks. Both designs also lack secure boot, leaving them vulnerable to firmware modification. We conclude that future BLE trackers must adopt stronger cryptography, authenticated firmware, and more resilient architectures to balance usability, privacy, and security in the growing Internet of Things (IoT) ecosystem.