An independent security researcher disclosed a zero-day vulnerability in the “Sign in with Apple” feature. If exploited, the vulnerability could have resulted in a full account takeover. The vulnerability has been patched, and Apple says it found no account misuse tied to it. Apple paid Bhavuk Jain a $100,000 bug bounty fee as a reward for the disclosure, which was revealed in a blog post on May 30. JWTs used to authenticate a user when attempting to sign in to a third-party app – a code generated by Apple.”]
Source: https://www.govinfosecurity.com/researcher-discloses-sign-in-apple-zero-day-flaw-a-14365

