A zero-day vulnerability was discovered in Apple's Sign in with Apple feature, which could have allowed an attacker to take over user accounts on third-party applications. The bug allowed an attacker to request JSON Web Tokens (JWTs) for any email ID from Apple, which would be verified as valid using Apple's public key. Apple paid $100,000 under their Security Bounty program to the researcher who discovered the bug. The vulnerability has been fixed and Apple found no evidence of misuse or account compromise.