Technology

Security flaw found in Sign in with Apple

‘Sign in with Apple’ is possibly more private than other login alternatives, yet it apparently incorporated a genuine security defect. Scientist Bhavuk Jain as of late got a $100,000 bug bounty for finding (by means of Hacker News) a defect in the sign-in administration when accessible through third-party applications. In the event that an application didn’t have its own security measures, an assailant could manufacture a token connected to any email ID and check it as “valid” utilizing Apple’s public key. That could permit a “full account takeover” regardless of whether you decided to conceal your email from different administrations, Jain said.

On hacker News, Jain said, “”I found I could request JWTs for any Email ID from Apple, and when the signature of these tokens was verified using Apple’s public key, they showed as valid. This means an attacker could forge a JWT by linking any Email ID and gaining access to the victim’s account,” Furthermore, “”The impact of this vulnerability was quite critical as it could have allowed a full account takeover. Many developers have integrated Sign in with Apple since it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple – Dropbox, Spotify, Airbnb, Giphy (now acquired by Facebook),” Bhavuk added.

Jain found the flaw in April, and it’s as of now fixed. Apple said there was no proof of accounts being undermined because of the flaw. There shouldn’t have been any harm done subsequently. In any case, the bug likely isn’t what Apple needed to think about in the wake of a string of security issues, including a previous Mail vulnerability. It’s fixing issues rapidly — the inquiry is whether it can eliminate these issues going ahead.

Read this OnePlus and McLaren partnership comes to an end

Recent Posts

Austin Fence Installation Contracts: 12 Clauses Homeowners Should Check in 2026

A fence proposal becomes useful only when it explains what will be built, who owns…

2 hours ago

Mouse for MMO players: Razer’s new Naga V3 Pro is a button monster

Razer is launching a new MMO mouse with the Naga V3 Pro. Three magnetic side…

1 day ago

Surface Phone: New images show discarded Microsoft prototype

It's an open secret that Microsoft was working on a Windows Phone smartphone long before…

1 day ago

How Solar Carport Structures Are Changing the Future of Sustainable Energy Infrastructure

As the demand for renewable energy continues to grow, businesses, municipalities, and property owners are…

1 day ago

What to do to find the right family law support in your case.

Family law issues seldom come at an opportune moment. Divorce, separation, parenting conflicts, child support,…

1 day ago

Claude AI data leak: Private chats were freely accessible on Google

Due to an insufficiently protected sharing function, private chat logs from the Anthropic AI Claude…

2 days ago