HomeSecurityCritical Zero-day vulnerability discovered in “Sign in with Apple”

Critical Zero-day vulnerability discovered in 'Sign in with Apple'

Sign in with Apple

A zero-day vulnerability in “ Sign in with Apple ” allows malicious actors to take control of accounts in the app simply by obtaining their email ID, a security researcher from India has discovered

Like OAuth 2.0, “Sign in with Apple” helps users log in to third-party apps faster, without having to fill out a lot of information, simply using their Apple ID.

This particular feature is used by thousands of users to log in to third-party apps such as Dropbox, Spotify, Airbnb, Giphy, and the bug has been classified as "critical" as it could allow remote attackers to take full control of an account.

Bhavuk Jain, the Indian security researcher who first discovered this bug, immediately reported it to Apple, saying: "Successful exploitation of the bug could result in full control of user accounts in this third-party app, regardless of whether a victim has a valid Apple ID or not."

About the zero-day vulnerability

Critical Zero-day vulnerability discovered in 'Sign in with Apple'

As Jain explains, Apple uses a JWT (JSON Web Token) generated by the Apple Server to authenticate a user, provide them with a secure email ID, and allow them to log in to the third-party app.

However, due to improper validation, the bug allows attackers to request a JWT for any email ID from Apple, which is then verified as valid using Apple's public key.

This allows the attacker to abuse JWTs to log in with any email ID and gain access to the victim's third-party account.

Jain also confirmed that the bug can also be exploited from the user's account, as Apple creates its own email ID for each user.

Apple rewarded the researcher with $100,000 for reporting the critical bug. Apple's security team confirmed that the bug was not exploited by any malicious actors after conducting an investigation and that it has now been fixed.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS