iMore has been able to reproduce a security breach that allowed malicious users to reset Apple ID passwords with nothing but an email and the user’s birthday. The security hole was a result of this not being properly enforced in Apple’s password reset process. When properly completed, step 4 would generate a complex URL something along the lines of:https://://://iforgot.apple.com/iForgot/resetPassword.html?forceBetterPlusPasswordRules=true&password=NEWPASSWORD&aolParameter=false&borderValue=true.”]
Source: https://gizmodo.com/how-apples-password-reset-security-breach-worked-5992117

