Blog | G5 Cyber Security

Researcher Discloses ‘Sign in with Apple’ Zero-Day Flaw

An independent security researcher disclosed a zero-day vulnerability in the “Sign in with Apple” feature. If exploited, the vulnerability could have resulted in a full account takeover. The vulnerability has been patched, and Apple says it found no account misuse tied to it. Apple paid Bhavuk Jain a $100,000 bug bounty fee as a reward for the disclosure, which was revealed in a blog post on May 30. JWTs used to authenticate a user when attempting to sign in to a third-party app – a code generated by Apple.”]

Source: https://www.govinfosecurity.com/researcher-discloses-sign-in-apple-zero-day-flaw-a-14365

Exit mobile version