Now Patched 'Sign in With Apple' Bug Left Users Open to Attack - MacRumors
Skip to Content

Now Patched 'Sign in With Apple' Bug Left Users Open to Attack

Researcher Bhavuk Jain in April discovered a critical Sign in With Apple vulnerability that could have resulted in a takeover of some user accounts. The bug was specific to third party apps that used Sign in With Apple and didn't implement additional security measures.

SigninwithApple e1590865553423
Jain notes that Sign in With Apple works by authenticating a user through a JWT (JSON Web Token) or a code that's generated by Apple's server. Apple then gives users the option to share either the email tied to their Apple ID or a private relay email address,which creates a JWT that's used to log in a user.

Jain then discovered that once JWTs for both Apple ID emails and private relay email addresses were requested and the token's signature was verified using Apple's public key, it "showed as valid." Should the bug have not been discovered, a JWT could be created and used to gain access to one's account.

In an interview with The Hacker News, Jain spoke about the severity of the bug:

The impact of the this vulnerability was quite critical as it could have allowed a full account takeover. Many developers have integrated Sign in with Apple since it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple - Dropbox, Spotify, Airbnb, Giphy (now acquired by Facebook).

According to Jain, Apple conducted an investigation and concluded that no accounts were compromised using this method before the vulnerability was patched. Jain was paid $100,000 by Apple under its Apple Security Bounty Program for reporting the bug.

Popular Stories

macOS Tahoe and iPhone

Anthropic's AI to Help Apple Find iOS, macOS, and Safari Vulnerabilities

Wednesday April 8, 2026 1:00 pm PDT by
Anthropic on Tuesday announced Project Glasswing, a new initiative that will enable tech companies to use its new AI model Mythos Preview to find and fix security vulnerabilities or weaknesses across operating systems and web browsers. Mythos Preview has already found thousands of zero-day vulnerabilities, including some in every major operating system and web browser, according to...
airpods pro 3 design

'AirPods Ultra' Rumored to Feature a Major Upgrade Over AirPods Pro

Thursday April 30, 2026 8:40 am PDT by
In a social media post this week, Bloomberg's Mark Gurman reiterated that Apple is planning to release new AirPods with cameras "for Siri." Last month, Gurman said these AirPods will likely be priced above the current AirPods Pro 3, which Apple sells for $249. As a result, he said Apple is likely considering using "AirPods Ultra" branding for the camera-equipped AirPods. "AirPods Ultra"...
Four iPhone 18 Pro Colors Mock Feature

iPhone 18 Pro to Launch in September With These 10 New Features

Tuesday April 28, 2026 9:35 am PDT by
While the iPhone 18 Pro and iPhone 18 Pro Max are not launching until September, there are already plenty of rumors about the devices. It was initially reported that the iPhone 18 Pro models would have fully under-screen Face ID, with only a front camera visible in the top-left corner of the screen. However, the latest rumors indicate that only one Face ID component will be moved under the...

Top Rated Comments

SBlue1 Avatar
77 months ago
100,000? Well deserved. :)
Score: 13 Votes (Like | Disagree)
B4U Avatar
77 months ago
Are we getting numb with the constant SW issues that Apple is having lately?
Score: 11 Votes (Like | Disagree)
Peace Avatar
77 months ago
I’m getting burned out on timmys security problems .

windows is looking better
Score: 10 Votes (Like | Disagree)
I7guy Avatar
77 months ago

I’m getting burned out on timmys security problems .

windows is looking better
Windows is better? Sure windows is as tight as a drum as far as that goes.

Just keep patching them Timmy.
Score: 7 Votes (Like | Disagree)
77 months ago

If it was unexploited and has been patched, there's not much of a story here… except to other businesses that might consider Sign In With Apple.
Bugs are a symptom, not the flaw. The constant stream of problems coming out from Apple shows their software development and QA processes are severely flawed.
Score: 5 Votes (Like | Disagree)
cmaier Avatar
77 months ago

I don't care.

I'm done updating.

I'm sick and tired of my phone being artificially slowed.

I'm back to using Linux for things that need to be secure, like banking, etc.
You know this wasn’t a bug in the client software or operating system, right?
Score: 5 Votes (Like | Disagree)