S
ign in with Apple is similar to other app login options such as “Sign in with Google” or Facebook; however, the difference is that Apple’s single sign-on offering is more private and even allows users to mask their email ID.
But Apple’s login method was hoarding a severe zero-day vulnerability that could have resulted in hackers taking over user accounts.
The bug was spotted back in April by an Indian developer, Bhavuk Jain, for which he received a whopping $100,000 in bug bounty. Thankfully, Apple has patched the vulnerability and says no accounts have been compromised.
According to Jain, the bug was specific to third-party apps, i.e., it only affected people who tried using “Sign in with Apple” in a third-party app.
Jain explains in his blogpost that the Apple login method authenticates a user either via JWT (JSON Web Token) or a code generated by Apple’s server. However, Jain noted that attackers could have forged a token linked to any email and could have verified it using Apple’s public key.
If the bug hadn’t been discovered, a hacker could have enjoyed a “full account takeover” despite a user masking their email.
The impact of this vulnerability was quite critical as it could have allowed a full account takeover. Many developers have integrated Sign in with Apple since it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple – Dropbox, Spotify, Airbnb, Giphy, Jain told The Hacker news
Apple introduced “Sign in with Apple” back in 2019 and brought the feature along with iOS 13. The best part about the feature is that a user can control the amount of data to be shared with an app.
Also Read: Hacker Breaks Into Stack Overflow Q&A Site, No Evidence of Data Breach
Also Read: Hacker Breaks Into Stack Overflow Q&A Site, No Evidence of Data Breach
tekirdağ
ReplyDeletetokat
elazığ
adıyaman
çankırı
OBYX
Adıyaman Lojistik
ReplyDeleteTrabzon Lojistik
Muğla Lojistik
Bayburt Lojistik
Bayburt Lojistik
CGYGYZ
98849
ReplyDeleteSakarya Evden Eve Nakliyat
Amasya Şehirler Arası Nakliyat
Sinop Şehir İçi Nakliyat
Ünye Fayans Ustası
Gümüşhane Şehir İçi Nakliyat
Bitmex Güvenilir mi
Çorlu Lojistik
Gölbaşı Parke Ustası
Giresun Lojistik
74711
ReplyDeleteHuobi Güvenilir mi
Iğdır Şehir İçi Nakliyat
Silivri Fayans Ustası
Kayseri Evden Eve Nakliyat
Tunceli Lojistik
Antalya Lojistik
Ünye Marangoz
Bilecik Lojistik
Kırklareli Parça Eşya Taşıma
F8E9F
ReplyDeleteÜnye Halı Yıkama
Yenimahalle Fayans Ustası
Bursa Şehir İçi Nakliyat
Manisa Şehirler Arası Nakliyat
Gölbaşı Fayans Ustası
Ankara Boya Ustası
Aydın Şehir İçi Nakliyat
Tekirdağ Şehir İçi Nakliyat
Sinop Şehir İçi Nakliyat
B8877
ReplyDeletewallet onekey
ellipal web
ledger
ledger desktop
ledger live app
web arculus wallet
web trust wallet
bitbox
wallet bitbox
1FE95
ReplyDeletepapatya sabunu
paribu
zerdeçal sabunu
bitexen
keçi sütü bal sabunu
mexc
bitexen
mercatox
binance referans kodu
71A04
ReplyDeletepoloniex
cointiger
https://kapinagelsin.com.tr/
referans kodu
coin nereden alınır
kizlarla canli sohbet
vindax
ilk kripto borsası
gate io
7C579
ReplyDeletewink görüntülü şov
D538C
ReplyDeletecanlı sanal show
8B602
ReplyDeletegörüntülü şov
76039
ReplyDeletegörüntülü şov
23F59
ReplyDeletewhatsapp görüntülü show güvenilir
D80EE7FC15
ReplyDeletetakipçi
85D6AC2D23
ReplyDeleteins bot basma