apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
apple patient
No Result
View All Result

“Sign in with Apple” – security hole closed

by Milan
31. May 2020 - 18:54
in Apple News
Galati, Romania, March 23, 2020: New iphone 11 Pro Max. iPhone 11 Pro is a smartphone developed by Apple Inc. Space gray smartphone back view on black background.

Galati, Romania, March 23, 2020: New iphone 11 Pro Max. iPhone 11 Pro is a smartphone developed by Apple Inc. Space gray smartphone back view on black background.

A critical security vulnerability allowed attackers to gain access to accounts that used “Sign in with Apple” – now Apple has fixed the bug. 

The vulnerability was discovered by Bhavuk Jain, a security researcher, and reported as part of Apple's Bug Bounty program. According to the report:

Bhavuk noted that while Apple requires users to sign in to their Apple account before triggering the request, it was not validated when the same person requested JSON Web Token (JWT) from their authentication server in the next step.

Therefore, the lack of validation in this part of the mechanism could have allowed an attacker to provide a separate Apple ID of a victim and thus trick Apple servers into generating JWT payload valid to log into a third-party service using the victim's identity.

$100,000 reward for the find

Therefore, accounts for third-party services created using "Sign in with Apple". Applications that have additional security measures for verification are excluded. Jain explained included: 

The impact of this vulnerability was quite critical as it could have allowed a complete takeover of the accounts. Many developers have integrated Sign in with Apple as it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple - Dropbox, Spotify, Airbnb, Giphy (now acquired by Facebook)," Jain wrote.

The security researcher received a total of 100,000 US dollars as a reward for this discovery. Apple has now reportedly closed the security hole. According to the company, however, the vulnerability was not exploited - at least there is no evidence of this. It should also be emphasized at this point that the Apple account itself was never at risk. (Photo by manae / Bigstockphoto)

Make Apfelpatient a preferred source One click – and you'll see us more often on Google
Was this article helpful?
YesNo
Tags: Apple ServiceiOSiPadOSmacOSsecurity gap

Our Amazon Storefront

A handpicked selection of products for iPhone, Mac and more – sorted by topic and updated regularly.

Shop Now

This post contains affiliate links (including Amazon). We earn a small commission on qualifying purchases – at no extra cost to you. Learn more on our Partner Program page.

Previous Post

Apple raises price for RAM

Next Post

Apple Watch Series 6: Leaker mentions display

Next Post
Alushta, Russia - November 6, 2018: Man hand with Apple Watch Series 4 with Heart Rate on the screen. Apple Watch was created and developed by the Apple inc.

Apple Watch Series 6: Leaker mentions display

Apple TV The Morning Show Season 5

Apple TV: The Morning Show ends with season 5

July 23, 2026
Apple Maps iOS 27

Apple Maps will be permanently installed in Ford electric cars by 2027

July 23, 2026
Google EU

EU imposes €890 million fine on Google

July 23, 2026

About APFELPATIENT

APFELPATIENT brings you the latest Apple news, product updates, guides, reviews and tips across the entire Apple ecosystem — from the iPhone to the Mac to the Apple Vision Pro. From the first rumors to confirmed news: researched responsibly.

Follow Apfelpatient

Facebook Instagram YouTube threads threads

Company

  • About Apfelpatient
  • Contact
  • Author Profiles

Community

  • Netiquette
  • Push Notifications
  • RSS feed

Legal

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • Cookie Settings
  • Affiliate Program

Resources

  • Sitemap

© 2026 Apfelpatient. All rights reserved.

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights

© 2026 Apfelpatient. All rights reserved. Page Directory

Change language to Deutsch