“Instead of seeding a target's parking lot with USB drives loaded with malware, an attacker can drop a maliciously prepared AirTag.”
arstechnica.com

Apple forgot to sanitize the Phone Number field for lost AirTags
Another bug-bounty boondoggle leads to public disclosure before the bug is fixed.
