iLoungeiLounge
  • News
    • Apple
      • AirPods Pro
      • AirPlay
      • Apps
        • Apple Music
      • iCloud
      • iTunes
      • HealthKit
      • HomeKit
      • HomePod
      • iOS 13
      • Apple Pay
      • Apple TV
      • Siri
    • Rumors
    • Humor
    • Technology
      • CES
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Font ResizerAa
iLoungeiLounge
Font ResizerAa
Search
  • News
    • Apple
    • Rumors
    • Humor
    • Technology
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Follow US

News › Apple

Apple

Apple Patches ‘Sign in With Apple’ Bug

Last updated: May 31, 2020 10:52 pm UTC
By Samantha Wiley
Apple

Last month researcher Bhavuk Jain discovered a bug while sighing in third party apps using Sign-in with Apple. This bug if not discovered could have taken over several Apple user accounts. The vulnerability occurred with only those third-party apps that did not use any extra security measures. 


According to Jain, Sign in With Apple authenticates a user through a code that is generated by Apple’s server or through a JSON Web Token.  Once authenticated, Apple gives the option to the users to share their private email or the one that is tied with their Apple ID. This email ID creates the JWT that is then used to log in.

Apple

Later Jain discovered that once the tokens for both email addresses were requested and Apple’s pubic key verified the token’s signature it “showed as valid.” If the bug was not discovered it could create a JWT and gain access to the user’s account. 

In an interview, Jain said that the impact of the bug was severe as it could allow a total takeover of the user’s account.

Apple rewarded Jain $100,000 for reporting the bug. Apple also conducted the investigation and it was discovered that no accounts were compromised before solving this issue by patching the bug. 


Latest News
The Apple Watch Series 11 42mm GPS is $100 Off
The Apple Watch Series 11 42mm GPS is $100 Off
1 Min Read
Apple Launching A New Education Hub In India Teaching Robotics and Swift Programming
Apple Launching A New Education Hub In India Teaching Robotics and Swift Programming
1 Min Read
Women’s and Men’s Golf Added to Apple Sports
Women’s and Men’s Golf Added to Apple Sports
1 Min Read
Apple Adding Civilization VII and Other Games To Apple Arcade
Apple Adding Civilization VII and Other Games To Apple Arcade
1 Min Read
AirPods 4 ANC Is $59 Off
AirPods 4 ANC Is $59 Off
1 Min Read
Apple Using 2NM Process For Their M6 and A20 Chip
Apple Using 2NM Process For Their M6 and A20 Chip
1 Min Read
iPhone 18 Models Will Not Have a Big Redesign
iPhone 18 Models Will Not Have a Big Redesign
1 Min Read
Launch of MacBook Pro M5 Pro and M5 Max Models is Approaching
Launch of MacBook Pro M5 Pro and M5 Max Models is Approaching
1 Min Read
Get the iPad Mini 7 256GB Wi-Fi at $99 Off
Get the iPad Mini 7 256GB Wi-Fi at $99 Off
1 Min Read
Mozilla Now Allows Turning AI Features Off
Mozilla Now Allows Turning AI Features Off
1 Min Read
Barcelona Passeig de Gràcia Apple Store Temporarily Closing
Barcelona Passeig de Gràcia Apple Store Temporarily Closing
1 Min Read
Apple’s Plans to Enter the Smart Glasses Market is Changing the Industry
Apple’s Plans to Enter the Smart Glasses Market is Changing the Industry
1 Min Read

iLounge logo

iLounge is an independent resource for all things iPod, iPhone, iPad, and beyond. iPod, iPhone, iPad, iTunes, Apple TV, and the Apple logo are trademarks of Apple Inc.

This website is not affiliated with Apple Inc.
iLounge © 2001 - 2025. All Rights Reserved.
  • Contact Us
  • Submit News
  • About Us
  • Forums
  • Privacy Policy
  • Terms Of Use
Welcome Back!

Sign in to your account

Lost your password?