Security News > 2020 > August > Apple Touch ID Flaw Could Have Let Attackers Hijack iCloud Accounts

Apple Touch ID Flaw Could Have Let Attackers Hijack iCloud Accounts
2020-08-05 04:28

Apple earlier this year fixed a security vulnerability in iOS and macOS that could have potentially allowed an attacker to gain unauthorized access to a user's iCloud account.

Uncovered in February by Thijs Alkemade, a security specialist at IT security firm Computest, the flaw resided in Apple's implementation of TouchID biometric feature that authenticated users to log in to websites on Safari, specifically those that use Apple ID logins.

After the issue was reported to Apple through their responsible disclosure program, the iPhone maker addressed the vulnerability in a server-side update.

Contrast this during logins to Apple domains the usual way with an ID and password, wherein the website embeds an iframe pointing to Apple's login validation server, which handles the authentication process.

Setting Up Fake Hotspots to Take Over iCloud Accounts In a separate scenario, the attack could be executed by embedding JavaScript on the web page that's displayed when connecting to a Wi-Fi network for the first time, thus allowing an attacker access to a user's account by just accepting a TouchID prompt from that page.


News URL

http://feedproxy.google.com/~r/TheHackersNews/~3/K88FpMmylxc/apple-touchid-sign-in.html

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Apple 68 212 1433 2208 257 4110