Apple ID password reset exploit reportedly in the wild
A new exploit lets anyone who knows your birthday and e-mail address reset your Apple ID password, according to a new report.
The exploit, described by The Verge though not posted publicly, makes use of a special URL that gets around the need for a security question, a security measure Apple put in place on all Apple ID accounts last April.
The reported exploit does not work on accounts with two-step verification enabled, which Apple introduced yesterday, and does away with the security question in favor of sending a four-digit PIN code to a cell phone that needs to be … Read more
