• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

iPhone Alarm Not Going Off? 2 Easy Fixes for iOS 26

May 5, 2026

Roborock Saros 20 review: Some of the best cleaning we’ve seen

May 4, 2026

Sihoo Doro C300 and C300 Pro V2 office chair reviews: Affordable, comfortable ergonomics

May 2, 2026
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Security»Critical Vulnerability In Apple Game Center Allowed Authentication Bypass
Security

Critical Vulnerability In Apple Game Center Allowed Authentication Bypass

June 25, 2022Updated:June 25, 2022No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Latest Hacking News
Share
Facebook Twitter LinkedIn Pinterest Email

Researchers found a vital vulnerability affecting the Apple Sport Middle that allowed authentication bypass. The bug usually existed within the Parse Server, exposing it to distant assaults.

Apple Sport Middle Vulnerability

In keeping with a latest advisory on GitHub, a vital authentication bypass vulnerability existed within the Parse Server, threatening Apple Sport Middle safety.

Particularly, Parse Server is an open-source backend server that customers can deploy on any infrastructure operating Node.js.

Explaining the impression of this vulnerability, the advisory reads,

The certificates in Apple Sport Middle auth adapter not validated. Consequently, authentication might probably be bypassed by making a faux certificates accessible through sure Apple domains and offering the URL to that certificates in an authData object.

The bug has acquired the identification quantity CVE-2022-31083, and a vital severity ranking, with a CVSS rating of 8.6. It affected Parse Server variations sooner than 4.10.11 and 5.2.2. The bug existed as a result of non-validation of the Parse Server Apple Sport Middle auth adapter. Therefore, any adversary might obtain an authentication bypass through faux certificates. As talked about within the NVD vulnerability description,

Previous to variations 4.10.11 and 5.2.2, the certificates within the Parse Server Apple Sport Middle auth adapter not validated. Consequently, authentication might probably be bypassed by making a faux certificates accessible through sure Apple domains and offering the URL to that certificates in an authData object.

Nonetheless, variations 4.10.11 and 5.2.2 tackle this flaw by introducing a brand new rootCertificateUrl property to the Parse Server Apple Sport Middle auth adapter. It “takes the URL to the foundation certificates of Apple’s Sport Middle authentication certificates”.

See also  Signal alerts 1,900 messaging users to a security threat from Twilio hackers

So, if builders haven’t set a worth for it, the brand new property defaults to the URL of the existing root certificate. The advisory urges builders to maintain the foundation certificates URL up to date when utilizing Parse Server Apple Sport Middle auth adapter.

For now, whereas the patch has arrived, no workaround is offered for the vulnerability.

Tell us your ideas within the feedback.

Source link

Allowed Apple Authentication Bypass Center Critical game Vulnerability
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

7 Essential Apple Notes Tips for iPhone in 2026

April 30, 2026

Widow’s Bay review: Apple TV’s genre mash-up is essential viewing

April 29, 2026

The 9 Best Ways to Reuse Your Old Apple Watch in 2026

April 24, 2026

iPhone 17e review: Apple core

March 11, 2026
Add A Comment

Comments are closed.

Editors Picks

Ugreen Revodok Pro 13-in-1 review

January 9, 2024

Flush with new cash, AssemblyAI looks to grow its AI-as-a-service business – DailyTech

July 14, 2022

Apple Eyes 2026 for Smart Glasses Debut, Axes Camera Watch

May 23, 2025

Anti-vax dating site exposed data for 3,500 users through ‘debug mode’ bug

July 25, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

iPhone Alarm Not Going Off? 2 Easy Fixes for iOS 26

Roborock Saros 20 review: Some of the best cleaning we’ve seen

Sihoo Doro C300 and C300 Pro V2 office chair reviews: Affordable, comfortable ergonomics

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.