Apple Security Breach: iForgot page Allows Cyber Attacks and Identity Theft


While the report on the vulnerability does not detail the process, it involves a malicious user pasting in a modified URL while answering the DOB security question on the iForgot page. Doing so allows for the resetting of a password, possibly giving another user access to the whole of an Apple ID account.

News of the exploit comes just the day after Apple enabled two-step verification for Apple IDs. Upon enabling the enhanced security feature, users can receive verification codes on their mobile devices, either through the Find My iPhone app or by text message. Those security codes are then used as a second verification method when making changes to an Apple ID account.


Follow us on Twitter:

Like us on facebook:

Download the “PFCSystems” app on BlackBerry World:


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s