"Sign in with Apple" Vulnerability
Tagsvulnerability
Full article87 words · extracted from schneier.com · click to collapse
Researcher Bhavuk Jain discovered a vulnerability in the “Sign in with Apple” feature, and received a $100,000 bug bounty from Apple. Basically, forged tokens could gain access to pretty much any account.
It is fixed.
EDITED TO ADD (6/2): Another story.
Tags: Apple, hacking, security engineering, vulnerabilities, zero-day
Comments
Subscribe to comments on this entry
Sidebar photo of Bruce Schneier by Joe MacInnis.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2020/06/sign_in_with_ap.html