iLoungeiLounge
  • News
    • Apple
      • AirPods Pro
      • AirPlay
      • Apps
        • Apple Music
      • iCloud
      • iTunes
      • HealthKit
      • HomeKit
      • HomePod
      • iOS 13
      • Apple Pay
      • Apple TV
      • Siri
    • Rumors
    • Humor
    • Technology
      • CES
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Font ResizerAa
iLoungeiLounge
Font ResizerAa
Search
  • News
    • Apple
    • Rumors
    • Humor
    • Technology
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Follow US

News

News

Apple rewards Indian developer for finding zero-day bug

Last updated: Jun 1, 2020 9:28 am UTC
By Abhay Ram
Book About Apple's 'Secrets' Lands on Amazon Germany's Bestseller List

An Indian developer reportedly received a $100,000 cheque from Apple for finding a bug in one of its products. A 27 year old developer named Bhavuk Jain is said to have found a bug in Apple’s “Sign In With Apple” system.


Jain said that he found a zero day bug in the Sign in with Apple system which could allow hackers to gain access to the user’s account when logging-in. Apple went on to acknowledge the critical security bug, the company also reportedly patched the bug and also found during its investigation that the bug had not been exploited. 

Book About Apple's 'Secrets' Lands on Amazon Germany's Bestseller List

“I found I could request JWTs for any Email ID from Apple and when the signature of these tokens was verified using Apple’s public key, they showed as valid. This means an attacker could forge a JWT by linking any Email ID to it and gaining access to the victim’s account,” said Jain.


Here’s my first 6 digit bounty from @Apple. Blog post will be up next week. #bugbounty pic.twitter.com/QygxvtGYJb

— Bhavuk Jain (@bhavukjain1) May 24, 2020

Sign in with Apple is Apple’s offering to allow developers to create an easier, simpler, and secure login system without much effort. Developers can add the “Sign in with Apple” button to their apps or on web platforms such as websites and web apps.

Apple introduced the ‘Sign in with Apple’ last June and said that users can also opt to not share their actual email ID but rather let Apple share a temporary email ID. Apple’s implementation of a secure login system is the best in the industry at the moment. 

However, Jain said in his explanation that Apple’s login system generates a JSON Web Token (JWT) which contains some information about the user and is sent to the app or website that the user is trying to log into.

According to Jain, the zero day bug he had found exposes the user information from the JSON Web Token. Apple has reported that it has fixed the issue now and has rewarded Jain handsomely.


Latest News
The AirPods Max Is $99 Off
The AirPods Max Is $99 Off
1 Min Read
Apple Music Uploads A Trailer For Upcoming Super Bowl Halftime Show
Apple Music Uploads A Trailer For Upcoming Super Bowl Halftime Show
1 Min Read
New Apple Store In Montreal Opens Its Doors
New Apple Store In Montreal Opens Its Doors
1 Min Read
Lisa Jackson Retiring From Apple
Lisa Jackson Retiring From Apple
1 Min Read
The 4-pack AirTag Is $34 Off
The 4-pack AirTag Is $34 Off 
1 Min Read
Filing For New Pro Display XDR/ Studio Display Discovered in Regulatory Database
Filing For New Pro Display XDR/ Studio Display Discovered in Regulatory Database
1 Min Read
Subscription Prices For Spotify are Rising Once Again
Subscription Prices For Spotify are Rising Once Again
1 Min Read
Shohei Ohtani Featured In Recent Ad Campaign For Beats
Shohei Ohtani Featured In Recent Ad Campaign For Beats
1 Min Read
The 13-inch M4 MacBook Air Is $200 Off
The 13-inch M4 MacBook Air Is $200 Off
1 Min Read
iPhone Fold Rumored To Be Made With Liquid Metal and ‘Better’ Titanium
iPhone Fold Rumored To Be Made With Liquid Metal and ‘Better’ Titanium
1 Min Read
Four New Games Coming to Apple Arcade
Four New Games Coming to Apple Arcade
1 Min Read
iPhone Shows ‘SOS Mode’ Due To Verizon Network Outage
iPhone Shows ‘SOS Mode’ Due To Verizon Network Outage
1 Min Read

iLounge logo

iLounge is an independent resource for all things iPod, iPhone, iPad, and beyond. iPod, iPhone, iPad, iTunes, Apple TV, and the Apple logo are trademarks of Apple Inc.

This website is not affiliated with Apple Inc.
iLounge © 2001 - 2025. All Rights Reserved.
  • Contact Us
  • Submit News
  • About Us
  • Forums
  • Privacy Policy
  • Terms Of Use
Welcome Back!

Sign in to your account

Lost your password?