Now Patched 'Sign in With Apple' Bug Left Users Open to Attack - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Now Patched 'Sign in With Apple' Bug Left Users Open to Attack

Researcher Bhavuk Jain in April discovered a critical Sign in With Apple vulnerability that could have resulted in a takeover of some user accounts. The bug was specific to third party apps that used Sign in With Apple and didn't implement additional security measures.

SigninwithApple e1590865553423
Jain notes that Sign in With Apple works by authenticating a user through a JWT (JSON Web Token) or a code that's generated by Apple's server. Apple then gives users the option to share either the email tied to their Apple ID or a private relay email address,which creates a JWT that's used to log in a user.

Jain then discovered that once JWTs for both Apple ID emails and private relay email addresses were requested and the token's signature was verified using Apple's public key, it "showed as valid." Should the bug have not been discovered, a JWT could be created and used to gain access to one's account.

In an interview with The Hacker News, Jain spoke about the severity of the bug:

The impact of the this vulnerability was quite critical as it could have allowed a full account takeover. Many developers have integrated Sign in with Apple since it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple - Dropbox, Spotify, Airbnb, Giphy (now acquired by Facebook).

According to Jain, Apple conducted an investigation and concluded that no accounts were compromised using this method before the vulnerability was patched. Jain was paid $100,000 by Apple under its Apple Security Bounty Program for reporting the bug.

Popular Stories

apple lock security bug vulnerability fix privacy

Apple Warns Canada's Bill C-22 Could Force Encryption Backdoors

Friday May 8, 2026 4:22 am PDT by
Apple and Meta have opposed a Canadian bill that the companies say could force them to create backdoor access to encrypted user data, should it pass through the country's parliament. Proposed by Canada's ruling Liberal Party, Bill C-22 contains provisions that could be similar ​to a UK data access provision order sent to Apple last year, depending on how they are implemented. Back in Feb...
macOS Tahoe and iPhone

Apple Alerted to macOS Security Vulnerability Uncovered With AI Tool

Thursday May 14, 2026 9:04 am PDT by
Anthropic recently announced Project Glasswing, an initiative that enables tech companies like Apple to use its new frontier AI model Claude Mythos Preview to find security vulnerabilities across operating systems and web browsers. The Wall Street Journal today reported that researchers at cybersecurity firm Calif used Claude Mythos Preview to uncover a new macOS security vulnerability last...
Apple Card iPhone 16 Pro Feature

Apple Card Promo to Offer Free AirPods Pro 3

Friday May 15, 2026 8:59 am PDT by
Starting as early as next week, customers who sign up for an Apple Card at Apple's retail stores in the U.S. will receive $249 cash back when they purchase AirPods Pro 3, according to Bloomberg's Mark Gurman. The promotion has yet to be officially announced by Apple, so exact terms and conditions are not available at this time. AirPods Pro 3 are priced at $249 in the U.S., so customers who...

Top Rated Comments

SBlue1 Avatar
78 months ago
100,000? Well deserved. :)
Score: 13 Votes (Like | Disagree)
B4U Avatar
78 months ago
Are we getting numb with the constant SW issues that Apple is having lately?
Score: 11 Votes (Like | Disagree)
Peace Avatar
78 months ago
I’m getting burned out on timmys security problems .

windows is looking better
Score: 10 Votes (Like | Disagree)
I7guy Avatar
78 months ago

I’m getting burned out on timmys security problems .

windows is looking better
Windows is better? Sure windows is as tight as a drum as far as that goes.

Just keep patching them Timmy.
Score: 7 Votes (Like | Disagree)
78 months ago

If it was unexploited and has been patched, there's not much of a story here… except to other businesses that might consider Sign In With Apple.
Bugs are a symptom, not the flaw. The constant stream of problems coming out from Apple shows their software development and QA processes are severely flawed.
Score: 5 Votes (Like | Disagree)
cmaier Avatar
78 months ago

I don't care.

I'm done updating.

I'm sick and tired of my phone being artificially slowed.

I'm back to using Linux for things that need to be secure, like banking, etc.
You know this wasn’t a bug in the client software or operating system, right?
Score: 5 Votes (Like | Disagree)