apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
  • iPhone 18
  • iOS 27
  • iPadOS 27
  • macOS
  • MacBook Neo
  • iPhone 17e
  • AirTags
  • iOS 26
  • iPhone 17
  • MacBook Pro
  • iPadOS
  • iMac
  • Mac mini
  • HomePod
  • Apple TV
  • iPad Pro
  • iPhone Air
  • Apple Vision Pro
  • iPhone 16
  • AirPods 4
  • Apple Watch Ultra
  • HomePod Mini
  • MacBook Air
  • iPad
  • AirPods Max
  • AirPods Pro 3
  • Apple Watch Series 3
  • Mac Studio
  • Studio Display
  • iPad Air
  • iPad mini
  • watchOS 27
  • Apple CarPlay
  • Apple Pay
  • watchOS 26
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
apple patient
No Result
View All Result

“Sign in with Apple” – security hole closed

Milan Jovicic by Milan Jovicic
31. May 2020 - 18:54 CEST
in Apple News
0
Galati, Romania, March 23, 2020: New iphone 11 Pro Max. iPhone 11 Pro is a smartphone developed by Apple Inc. Space gray smartphone back view on black background.

Galati, Romania, March 23, 2020: New iphone 11 Pro Max. iPhone 11 Pro is a smartphone developed by Apple Inc. Space gray smartphone back view on black background.

WhatsAppFacebookEmail
Threads

A critical security vulnerability allowed attackers to gain access to accounts that used “Sign in with Apple” – now Apple has fixed the bug. 

The vulnerability was discovered by Bhavuk Jain, a security researcher, and reported as part of Apple's Bug Bounty program. According to the report:

Bhavuk noted that while Apple requires users to sign in to their Apple account before triggering the request, it was not validated when the same person requested JSON Web Token (JWT) from their authentication server in the next step.

Therefore, the lack of validation in this part of the mechanism could have allowed an attacker to provide a separate Apple ID of a victim and thus trick Apple servers into generating JWT payload valid to log into a third-party service using the victim's identity.

$100,000 reward for the find

Therefore, accounts for third-party services created using "Sign in with Apple". Applications that have additional security measures for verification are excluded. Jain explained included: 

The impact of this vulnerability was quite critical as it could have allowed a complete takeover of the accounts. Many developers have integrated Sign in with Apple as it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple - Dropbox, Spotify, Airbnb, Giphy (now acquired by Facebook)," Jain wrote.

The security researcher received a total of 100,000 US dollars as a reward for this discovery. Apple has now reportedly closed the security hole. According to the company, however, the vulnerability was not exploited - at least there is no evidence of this. It should also be emphasized at this point that the Apple account itself was never at risk. (Photo by manae / Bigstockphoto)

Make Apfelpatient a preferred source One click – and you'll see us more often on Google
Was this article helpful?
YesNo
Tags: Apple ServiceiOSiPadOSmacOSsecurity gap
SendShareSend
Share

Our Amazon Storefront

A handpicked selection of products for iPhone, Mac and more – sorted by topic and updated regularly.

Shop Now

This post contains affiliate links (including Amazon). We earn a small commission on qualifying purchases – at no extra cost to you. Learn more on our Partner Program page.

Previous Post

Apple raises price for RAM

Next Post

Apple Watch Series 6: Leaker mentions display

Milan Jovicic

Milan Jovicic

Milan founded Apfelpatient in 2016 and has been responsible for all editorial content since 2018 — news, rumors, guides, and product reviews. Apple devices here are not test units on loan for two weeks but everyday tools: from the iPhone through MacBook Pro, MacBook Air, and iMac to the Apple Vision Pro, at least one device from nearly every product category is in daily use, many of them replaced annually. Every menu path in a guide is verified on the device before it is published.

Key art for the Apple TV series Pluribus showing a screaming woman against a yellow background, with Pluribus season 2 about to begin filming

Pluribus: Gilligan plans at least three seasons

August 12, 2026 - 8:27 PM CEST
The iPhone 17 lineup in five colors seen from the back, whose successor is expected to adopt the smaller iPhone 18 Dynamic Island from the Pro models

iPhone 18: Smaller Dynamic Island already in the base model

August 12, 2026 - 8:13 PM CEST
Drawn outline of the folded iPhone Ultra with square corners on the hinge side and rounded corners opposite, matching the leaked iPhone Ultra screen protectors

iPhone Ultra: Screen protectors reveal the camera position

August 12, 2026 - 3:58 PM CEST

About APFELPATIENT

APFELPATIENT brings you the latest Apple news, product updates, guides, reviews and tips across the entire Apple ecosystem — from the iPhone to the Mac to the Apple Vision Pro. From the first rumors to confirmed news: researched responsibly.

Follow Apfelpatient

Facebook Instagram YouTube Threads Threads

Company

  • About Apfelpatient
  • Contact
  • Author Profiles

Community

  • Netiquette
  • Push Notifications
  • RSS feed

Legal

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • Cookie Settings
  • Affiliate Program

Resources

  • Sitemap

© 2026 Apfelpatient. All rights reserved.

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights

© 2026 Apfelpatient. All rights reserved. Page Directory

Change language to Deutsch