iLoungeiLounge
  • News
    • Apple
      • AirPods Pro
      • AirPlay
      • Apps
        • Apple Music
      • iCloud
      • iTunes
      • HealthKit
      • HomeKit
      • HomePod
      • iOS 13
      • Apple Pay
      • Apple TV
      • Siri
    • Rumors
    • Humor
    • Technology
      • CES
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Font ResizerAa
iLoungeiLounge
Font ResizerAa
Search
  • News
    • Apple
    • Rumors
    • Humor
    • Technology
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Follow US

News › Apple

Apple

Apple Patches ‘Sign in With Apple’ Bug

Last updated: May 31, 2020 10:52 pm UTC
By Samantha Wiley
Apple

Last month researcher Bhavuk Jain discovered a bug while sighing in third party apps using Sign-in with Apple. This bug if not discovered could have taken over several Apple user accounts. The vulnerability occurred with only those third-party apps that did not use any extra security measures. 


According to Jain, Sign in With Apple authenticates a user through a code that is generated by Apple’s server or through a JSON Web Token.  Once authenticated, Apple gives the option to the users to share their private email or the one that is tied with their Apple ID. This email ID creates the JWT that is then used to log in.

Apple

Later Jain discovered that once the tokens for both email addresses were requested and Apple’s pubic key verified the token’s signature it “showed as valid.” If the bug was not discovered it could create a JWT and gain access to the user’s account. 

In an interview, Jain said that the impact of the bug was severe as it could allow a total takeover of the user’s account.

Apple rewarded Jain $100,000 for reporting the bug. Apple also conducted the investigation and it was discovered that no accounts were compromised before solving this issue by patching the bug. 


Latest News
AirPods Max 2 is $20 off
AirPods Max 2 is $20 off
1 Min Read
Apple and John Giannandrea Part Ways
Apple and John Giannandrea Part Ways
1 Min Read
Huawei Unveils Foldable Device
Huawei Unveils Foldable Device
1 Min Read
Mass Production for iPhone Fold Delayed
Mass Production for iPhone Fold Delayed
1 Min Read
AirPods Pro 3 is $49 off
AirPods Pro 3 is $49 off
1 Min Read
Valve Announces Stream Link App For Vision Pro Headset
Valve Announces Stream Link App For Vision Pro Headset
1 Min Read
Apple Using Smart Adhesive for Foldable iPhone
Apple Using Smart Adhesive for Foldable iPhone
1 Min Read
Apple Creating Different Styles for Smart Glasses
Apple Creating Different Styles for Smart Glasses
1 Min Read
14-inch M5 Pro MacBook Pro 24GB 1TB Is $149 Off
14-inch M5 Pro MacBook Pro 24GB 1TB Is $149 Off
1 Min Read
Shipment For Apple Mac Increases
Shipment For Apple Mac Increases
1 Min Read
Developer Integrates Mac OS X Cheetah for the Nintendo Wii
Developer Integrates Mac OS X Cheetah for the Nintendo Wii
1 Min Read
New Subscription Added by OpenAI
New Subscription Added by OpenAI
1 Min Read

iLounge logo

iLounge is an independent resource for all things iPod, iPhone, iPad, and beyond. iPod, iPhone, iPad, iTunes, Apple TV, and the Apple logo are trademarks of Apple Inc.

This website is not affiliated with Apple Inc.
iLounge © 2001 - 2025. All Rights Reserved.
  • Contact Us
  • Submit News
  • About Us
  • Forums
  • Privacy Policy
  • Terms Of Use
Welcome Back!

Sign in to your account

Lost your password?