Apple awards hacker $100,000 for discovering a Sign In With Apple vulnerability

A vulnerability inside Sign In With Apple could have potentially allowed hackers to take over your linked, third-party accounts. Discovered by India-based security researcher Bhavuk Jain in April, Apple has since patched the loophole, and in recognition of the discovery, awarded Jain a bug bounty of $100,000.

Sign-in platforms, including the one by Apple, protect user identity by exchanging a token with the third-party service instead of providing a set of private credentials. This token is produced every time you click, in Apple’s case, the Sign-In With Apple button, and lets the third party authenticate you by running it through Apple’s database.

The bug that Bhavuk came across affected how Apple’s authentication service confirmed who was requesting that token in a session. While Sign-In With Apple needed a valid Apple account to work, it wasn’t verifying whether that same account was the one requesting a token. Therefore, irrespective of the device’s linked Apple account, Bhavuk was able to retrieve a token for any Apple ID and use that to illicitly take over its connected, third-party account.

Even though the victim’s Apple account wasn’t compromised, since that’s never directly revealed in the process, this loophole could have enabled intruders to log into any of the account’s Sign-In With Apple apps. It’s also worth noting that the bug would have proved detrimental only when the third-party service itself didn’t have any additional privacy protections of its own.

“The impact of this vulnerability was quite critical as it could have allowed full account takeover. A lot of developers have integrated Sign in with Apple since it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple – Dropbox, Spotify, Airbnb, Giphy (Now acquired by Facebook). These applications were not tested but could have been vulnerable to a full account takeover if there weren’t any other security measures in place while verifying a user,” wrote Bhavuk in a blog post.

Apple told Bhavuk, after investigating its internal logs, that “there was no misuse or account compromise due to this vulnerability.”

Launched about a year ago, Apple has centered its sign-in service around the idea of a more private and secure login experience. It has been adopted by a number of developers and companies including Airbnb, Dropbox, Adobe, TikTok, and more. It’s unclear for how long this vulnerability was left in the open and how far-reaching its effects would be on early adopters’ trust in the sign-in service. We’ve reached out to Apple regarding the same and we’ll update the story when we hear back.

Latest posts

‘It’s a risk’: Wonder Man showrunner says the new Disney+ show is a ‘big swing’ for Marvel — and could ‘alienate’ some of the...

Wonder Man is a "big swing creatively for Marvel", according to its showrunnerAndrew Guest says it could also "alienate some hardcore fans"The next MCU...

Major Microsoft 365 outage left users without access to emails and files – here’s what we know

MO1221364 Microsoft 365 outage has now been fixedMicrosoft says parts of its North America infrastructure were to blameHours of rebalancing and refining preceded a...

One game surprised me the most in the Xbox Developer Direct — and it’s a wacky brawler that’s releasing this year

Xbox Game Studios has revealed pottery themed brawler Kiln It comes from Double Fine, the studio behind games like PyschonautsIt's out this year and...

Forza Horizon 6’s Developer Direct showcase was brilliant — these three big changes are what excite me most about the upcoming open-world racing game,...

Forza Horizon 6 was showcased for the first time at the most recent Xbox Developer DirectBig changes include revamps to career progression, and creative...

I test vacuums for a living – these are the 3 best cheap stick vacuums you can buy

No one wants to spend a fortune on something as mundane as a vacuum cleaner, but choosing a cheap vacuum is a risky process...

Best Buy’s Presidents’ Day preview sale is live — here are 35 deals I’d buy on TVs, appliances, laptops and more

As most of the country tries to stay warm (and safe) this weekend, Best Buy has launched a massive sale that feels like a...

The deal to keep TikTok in the US is now finalized – here are 5 things you need to know

TikTok has finalized a deal to keep operating in the USOriginal owner ByteDance retains a 19.9% shareThe TikTok algorithm will be retrained for users...

Crowdstrike and Nord Security partnership nests Falcon Go and Falcon Enterprise directly through NordLayer – combined enterprise-grade protection with VPN and ZTNA for SMBs

CrowdStrike and Nord announce wider tie-upPartnership will see Falcon Go and Falcon Enterprise integrated into NordLayerLooks to help SMBs deal with growing security concernsA...

CD Projekt Red’s The Witcher 4 may be up there with GTA 6 in rumored production costs

CD Projekt Red's The Witcher 4 is rumored to cost nearly $1 billionA Polish analyst claims it's costing around $390 million apiece for development...

Beast of Reincarnation director says Game Freak’s priority is delivering a quality ‘gameplay experience’ rather than graphical fidelity — but the game still certainly...

Beast of Reincarnation director Kota Furushima has said Game Freak's priority is delivering a good "gameplay experience"The director says graphics and performance are important,...