Apple Pays Indian Developer Rs. 75 Lakh for Finding a Bug in ‘Sign in With Apple’ Process

The ‘Sign in with Apple’ Zero Day bug could give hackers a complete account takeover.

Advertisement
By Vineet Washington | Updated: 1 June 2020 14:01 IST
Highlights
  • Indian developer found vulnerability in Sign in with Apple process
  • He was paid $100,000 (roughly Rs. 75.3 lakh) for finding it
  • The flaw could allow complete account takeover

The vulnerability has reportedly been patched

Photo Credit: Bhavukjain.com

Apple has reportedly paid an Indian developer $100,000 (roughly Rs. 75.3 lakh) for finding a critical bug in the ‘Sign in with Apple' process on its devices. The 27-year-old developer named Bhavuk Jain had discovered a Zero Day bug in the 'Sign in with Apple' process that could have allowed hackers to gain access to the user's account where they were trying to sign in. The Cupertino-based company acknowledged this bug and stated that it had investigated and patched it, adding that this flaw was not exploited.

What is ‘Sign in with Apple'?

Jain disclosed this flaw in Apple's ‘Sign in with Apple' process that he found in April, on May 30 through a blog post. The ‘Sign in with Apple' feature was introduced in June last year. This feature allows Apple account holders to sing in to third part apps without having to share their email address. This is done by generating a JSON Web Token (JWT) containing information required by the third-party application to confirm the identity of the user. While this process was implemented to preserve user privacy, the Zero Day bug found by Jain exposes the user accounts to attacks.

Advertisement

Sign in with Apple bug

According to the blog post by Jain, it was found that while signing in with Apple, users are required to log-in to their Apple account, which is the first step. In the second step, however, it was found that there was no validation to check if the same user is requesting a JWT to login to a third party app. This, as explained by Jain, could allow a hacker takeover the user's account by faking a JWT.

“I found I could request JWTs for any Email ID from Apple and when the signature of these tokens was verified using Apple's public key, they showed as valid. This means an attacker could forge a JWT by linking any Email ID to it and gaining access to the victim's account,” Jain said. The developer went on to state that the impact of this flaw is “quite critical” and that it could allow a full account takeover. This in turn, would give hackers access to a lot of personal user data that might include log in credentials, passwords, account details, and other such private information.

Advertisement

 

While not many apps support this sign in process, it is available for Dropbox, Giphy, Spotify, and Airbnb, among others. Additionally, several other apps have this feature but not as a mandate. However, it still puts users at risk and as per the blog post, Apple conducted its own investigation of its logs and stated that no account has been compromised due to this vulnerability. Jain was paid $100,000 (roughly Rs. 75.3 lakh) by Apple under its Apple Security Bounty program for discovering and reporting this vulnerability.


Is Realme TV the best TV under Rs. 15,000 in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week (Mar 30th - Apr 5th): From Aamir Khan's Sitaare Zameen Par
  2. Vivo V70 FE Launched in India With 7,000mAh Battery, 200-Megapixel Main Camera
  3. Realme 16 5G Launched in India With Selfie Mirror Feature: Check Price
  4. Infinix Note 60 Pro With Active Matrix Panel to Arrive in India on This Date
  5. Redmi Note 15 SE 5G Debuts in India With a Vegan Leather Finish: See Price
  6. Best Mobiles Under Rs. 30,000 in India
  7. Honor X80i With MediaTek Dimensity 6500 Elite Chip Launched: See Price
  8. Govt Spends 180 Crore to Move Lakhs of Official Email to Zoho Cloud
  9. Sony Xperia 1 VIII Leak Suggests These Big Design Changes Are on The Way
  1. Apple's iPhone 18 Pro Models May Not Arrive in Classic Black Finish Just Like iPhone 17 Pro, Tipster Claims
  2. Oppo F33, Oppo F31 Pro Launch Timeline, Price Range Revealed in New Leak
  3. Capcom Adds Original Versions of Resident Evil 1, 2 and Resident Evil 3 Nemesis to Steam
  4. Google's Next Fitbit Wearable Could Launch Without a Display; Said to Require Paid Subscription
  5. CFTC-FTX Settlement: Former FTX Executive Nishad Singh to Pay $3.7 Million, Faces Trading Ban
  6. Slack Upgrades Slackbot With New AI Features to Turn It Into an Enterprise Agent
  7. Australia Mandates Financial Services Licences for Crypto Exchanges Under New Bill
  8. DoT Reportedly Extends SIM Binding Mandate Till the End of 2026
  9. Government Migrates 16.68 Lakh Official Email Accounts to Zoho Cloud, Spends Rs. 180 Crore
  10. Infinix Note 60 Pro India Launch Date Revealed; Company Teases Active Matrix Feature on Rear Panel
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.