Infinite Diaries
  • Webcolumn
  • Software / Apps
  • Hardware
  • Travel
  • Photography
  • Where I’ve Been
  • Linked
  • Microblog
  • Search
  • Polski

Sign in with Apple

Zero-Day in Sign in With Apple →

May 31, 2020 · 14:36

Bhavuk Jain:

In the month of April, I found a zero-day in Sign in with Apple that affected third-party applications which were using it and didn’t implement their own additional security measures. This bug could have resulted in a full account takeover of user accounts on that third party application irrespective of a victim having a valid Apple ID or not.

For this vulnerability, I was paid $100,000 by Apple under their Apple Security Bounty program.


© Wojtek Pietrusiewicz · Powered by zenbox.pl · Mastodon · Instagram · RSS · JSON Feed · Return to top