Skip to main content
  1. Home
  2. Phones
  3. Mobile
  4. News

Apple awards hacker $100K for finding a Sign In With Apple vulnerability

Add as a preferred source on Google

A vulnerability inside Sign In With Apple could have potentially allowed hackers to take over your linked, third-party accounts. Discovered by India-based security researcher Bhavuk Jain in April, Apple has since patched the loophole, and in recognition of the discovery, awarded Jain a bug bounty of $100,000.

Sign-in platforms, including the one by Apple, protect user identity by exchanging a token with the third-party service instead of providing a set of private credentials. This token is produced every time you click, in Apple’s case, the Sign-In With Apple button, and lets the third party authenticate you by running it through Apple’s database.

Recommended Videos

The bug that Bhavuk came across affected how Apple’s authentication service confirmed who was requesting that token in a session. While Sign-In With Apple needed a valid Apple account to work, it wasn’t verifying whether that same account was the one requesting a token. Therefore, irrespective of the device’s linked Apple account, Bhavuk was able to retrieve a token for any Apple ID and use that to illicitly take over its connected, third-party account.

Even though the victim’s Apple account wasn’t compromised, since that’s never directly revealed in the process, this loophole could have enabled intruders to log into any of the account’s Sign-In With Apple apps. It’s also worth noting that the bug would have proved detrimental only when the third-party service itself didn’t have any additional privacy protections of its own.

“The impact of this vulnerability was quite critical as it could have allowed full account takeover. A lot of developers have integrated Sign in with Apple since it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple – Dropbox, Spotify, Airbnb, Giphy (Now acquired by Facebook). These applications were not tested but could have been vulnerable to a full account takeover if there weren’t any other security measures in place while verifying a user,” wrote Bhavuk in a blog post.

Apple told Bhavuk, after investigating its internal logs, that “there was no misuse or account compromise due to this vulnerability.”

Launched about a year ago, Apple has centered its sign-in service around the idea of a more private and secure login experience. It has been adopted by a number of developers and companies including Airbnb, Dropbox, Adobe, TikTok, and more. It’s unclear for how long this vulnerability was left in the open and how far-reaching its effects would be on early adopters’ trust in the sign-in service. We’ve reached out to Apple regarding the same and we’ll update the story when we hear back.

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
I tried a hidden video trick in iOS 27, and it saved me a ton of frustration
Better quality, smaller file size, and no status bar. iOS 27's video frame feature beats screenshots on every count.
Electronics, Mobile Phone, Phone

If you've ever been on vacation and chose to record video instead of taking photos only to avoid missing the fun moments, thinking you’d pause and take screenshots later, you might have ended up questioning your decision later. 

You see, the process involves multiple steps, starting from hunting for the right frame, pausing, and taking a screenshot. If it doesn’t look good, you go back to the video, pause somewhere else, and try taking another screenshot. You see where I’m going with this?

Read more
iPhone 18 Pro images are already floating on the dark web with a whole bunch of other Apple secrets
A ransomware attack on Tata Electronics reportedly exposed confidential documents tied to Apple's next flagship.
Apple iPhone 17 Pro White

Apple is famous for keeping future iPhones under lock and key. This time, however, the leak didn't come from a case maker or an overenthusiastic tipster. According to Reuters, confidential files linked to the iPhone 18 Pro have surfaced on the dark web following a cyberattack on Tata Electronics, one of Apple's most important manufacturing partners in India.

The leak goes far beyond a few blurry photos

Read more
Apple has six new iPhones lined up for 2027 with some serious upgrade muscle
The 2027 iPhone lineup looks stacked
Electronics, Phone, Mobile Phone

Apple's iPhone launch calendar may get a lot busier in 2027. A new leak claims the company has six new iPhone models lined up across the year, and if most of it is accurate, we could be looking at the biggest iPhone roadmap in years.

According to known tipster, Digital Chat Station, Apple’s early 2027 lineup could include the iPhone Air 2, iPhone 18, and iPhone 18e. The fall lineup is expected to bring next-generation Pro models and a second foldable iPhone, reportedly referred to as iPhone Ultra 2.

Read more