4 ms·
To me this seems like a poor protocol design that created an opportunity for an implementation error, and that opportunity was seized. In the initial authoriza
by kag0 6y ago
To me this seems like a poor protocol design that created an opportunity for an implementation error, and that opportunity was seized.
In the initial authorization request rather than passing a string with an email address, the caller could pass a boolean `usePrivateRelay`. If true generate a custom address for the third party, if false use the email address on file.
With that one change the implementer no longer has the opportunity to forget to validate the provided email address, and the vuln is impossible.
- m_herrlich 6y agoYou misunderstand the bug, the exploit allows an attacker to generate an apple-signed JWT with an email address of the attacker's choice.