ZeroHour
Schneier on Securitypublished ()ingested

"Sign in with Apple" Vulnerability

criticalVulnerabilityimportance 55
Full article87 words · extracted from schneier.com · click to collapse

HomeBlog

Researcher Bhavuk Jain discovered a vulnerability in the “Sign in with Apple” feature, and received a $100,000 bug bounty from Apple. Basically, forged tokens could gain access to pretty much any account.

It is fixed.

EDITED TO ADD (6/2): Another story.

Tags: Apple, hacking, security engineering, vulnerabilities, zero-day

Posted on June 2, 2020 at 6:27 AM15 Comments

Comments

Atom Feed Subscribe to comments on this entry

Sidebar photo of Bruce Schneier by Joe MacInnis.

Powered by WordPress Hosted by Pressable

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2020/06/sign_in_with_ap.html