Schneier - "Sign in with Apple" Vulnerability
Researcher Bhavuk Jain discovered a vulnerability in the "Sign in with Apple" feature, and received a $100,000 bug bounty from Apple. Basically, forged tokens could gain access to pretty much any account.
It is fixed.
from Schneier on Security https://www.schneier.com/blog/archives/2020/06/sign_in_with_ap.html
Comments
Post a Comment