Get a Pentest and security assessment of your IT network.

Cyber Security

Critical ‘Sign in with Apple’ Bug Could Have Let Attackers Hijack Anyone’s Account

Apple recently paid Indian vulnerability researcher Bhavuk Jain a huge $100,000 bug bounty for reporting a highly critical vulnerability affecting its ‘Sign in with Apple’ feature. The vulnerability resided in the way Apple was validating a user on the client-side before initiating a request from Apple’s authentication servers. The missing validation in that part of the mechanism could have allowed an attacker to provide a separate Apple ID belonging to a victim, tricking Apple servers into generating JWT payload that was valid to sign in into a 3rd-party service.

Source: https://thehackernews.com/2020/05/sign-in-with-apple-hacking.html

Related posts
Cyber Security

Zip Codes & PII: Are They Personal Data?

Cyber Security

Zero-Day Vulnerabilities: User Defence Guide

Cyber Security

Zero Knowledge Voting with Trusted Server

Cyber Security

ZeroNet: 51% Attack Risks & Mitigation