Apple had announced Sign in with Apple in 2019 to allow users (with an Apple ID) to simply and quickly sign into third-party apps and websites.

A full-stack developer from India apparently found a critical flaw in “Sign in with Apple” account authentication in April that could have potentially allowed hackers to fully take over any account linked to it. 27-year-old Bhavuk Jain claimed in a blog post that he had reported the bug to Apple before disclosing it to the public on Saturday. Apple has since fixed the issue, and paid him $100,000 (nearly 75 lakh Rupees) as part of the Apple Security Bounty program, he added.
Apple had announced Sign in with Apple in 2019 to allow users (with an Apple ID) to simply and quickly sign into third-party apps and websites, its main USP being that it was supposed to be more private and secure than more conventional sign-ins via Google and Facebook. While social sign-ins may be used to collect users’ personal data, Sign in with Apple promised a completely anonymous approach. You could, for instance, sign up with apps and services without disclosing your Apple ID.


As it turns out, the whole system was marred by a zero day vulnerability, according to Jain, that could have allowed anybody with your email address and the technical know-how to spoof the Apple ID servers and gain access to all your online accounts. This was especially true for accounts linked to apps and websites that did not deploy any security measures of their own.
“The Sign in with Apple works similarly to OAuth 2.0. I found I could request JWTs (JSON Web Tokens) for any Email ID from Apple and when the signature of these tokens was verified using Apple’s public key, they showed as valid,” Jain said. “This means an attacker could forge a JWT by linking any Email ID to it and gaining access to the victim’s account.”
Apple has made Sign in with Apple “mandatory” for all all applications that support other social logins. Dropbox and Spotify are two examples. “The impact of this vulnerability was quite critical as it could have allowed full account takeover,” Jain said.
But more importantly, Apple apparently “did an investigation of their logs and determined there was no misuse or account compromise due to this vulnerability.” Apple is yet to publicly acknowledge the flaw.

Uttar Pradesh hikes monthly stipend for Ayurveda, Unani and Homoeopathy interns to ₹15,000

Kerala university protest turns tense as police use water cannons against SFI demonstrators

BML Munjal University Hosts ICATS 2026 Conference on AI, Global Trade and Sustainability

NAMSCON 2026: SRMIST Founder Chancellor Dr. T. R. Paarivendhar Stresses Multidisciplinary Healthcare Approach

Hisar law graduate secures fifth rank in HCS exam, used ChatGPT during preparation

Ken Griffin’s record $3 billion gift to Carnegie Mellon to fuel new Miami campus

Michael Jordan pledges $10 million to UNC social work school in mother’s honour
.jpg&w=256&q=75)
University of Arizona suspends fraternity activities as misconduct reports mount
.jpg&w=256&q=75)
Cornell rape accuser was misled about criminal probe, lawyer alleges
.webp&w=256&q=75)
Over 1,000 US colleges fail to submit student outcomes data by deadline

Uttar Pradesh hikes monthly stipend for Ayurveda, Unani and Homoeopathy interns to ₹15,000

Kerala university protest turns tense as police use water cannons against SFI demonstrators

BML Munjal University Hosts ICATS 2026 Conference on AI, Global Trade and Sustainability

NAMSCON 2026: SRMIST Founder Chancellor Dr. T. R. Paarivendhar Stresses Multidisciplinary Healthcare Approach

Hisar law graduate secures fifth rank in HCS exam, used ChatGPT during preparation

Ken Griffin’s record $3 billion gift to Carnegie Mellon to fuel new Miami campus

Michael Jordan pledges $10 million to UNC social work school in mother’s honour
.jpg&w=256&q=75)
University of Arizona suspends fraternity activities as misconduct reports mount
.jpg&w=256&q=75)
Cornell rape accuser was misled about criminal probe, lawyer alleges
.webp&w=256&q=75)
Over 1,000 US colleges fail to submit student outcomes data by deadline
Copyright© educationpost.in 2024 All Rights Reserved.
Designed and Developed by @Pyndertech