Arriving right on the coat tails of Apple’s two-step verification implementation, a new security flaw has been found in Apple’s password reset process for Apple IDs. The vulnerability allows an attacker to reset your Apple ID’s password with only the knowledge of your Apple ID and date of birth, completely bypassing the need to answer your security questions. The Verge first reported the vulnerability after being tipped off to the hack.
iMore was independently able to reproduce the hack and confirm its validity. It is accomplished by using a specially crafted URL that is able to reset your password once you have validated your date of birth, but before the security questions have actually been answered.
The good news is that users who have enabled two-step verification with Apple are not vulnerable. The bad news is some users have been getting a three-day waiting period to enable two-step verification, in order to minimize the risk of a malicious party enabling two-factor verification on a compromised account. The worse news is that two-step verification is not yet available in many countries. According to the Apple FAQ:
Initially, two-step verification is being offered in the U.S., UK, Australia, Ireland, and New Zealand. Additional countries will be added over time. When your country is added, two-step verification will automatically appear in the Password and Security section of Manage My Apple ID when you sign in to My Apple ID.
If you are unable to enable two-step verification at this time, your next best bet is to change your date of birth on record with Apple in order thwart any attempts on your account by somebody who knows your email and birthdate. Since this is a server-side vulnerability, Apple will hopefully be able to deploy a fix shortly, before information of how to exploit the flaw spreads.
Update: It looks like Apple has taken the iForgot page down.
Currently Unavailable
Sorry, the site is currently unavailable due to maintenance. Please check back later.
Update 2: After Apple updated the password reset page to say it was down for maintenance, presumably to prevent any further attempts to use this exploit, it was discovered by iMore that the password reset hack could still be performed by providing a specific URL to bypass the maintenance page. Apple was notified and has since made the entire site completely inaccessible.
Update 3: Apple has fixed the security hole and iForgot is back up.
Update 4: A detailed look at how the exploit worked can be found here.
We may earn a commission for purchases using our links. Learn more.

Gorgeous new Pride Apple Watch bands are now available at some Apple Stores
Apple's latest Pride Apple Watch bands are now available to buy in some Apple Stores, although whether you can walk into a store and pick one up yourself will very much depend on where you happen to be.

Rare Steve Jobs check for $9.18 goes under the hammer, could fetch $25k
A rare check signed by Steve Jobs dated July 23, 1976, has just gone up for auction and could be worth a lot more than it was originally written out for...

Apple store workers get surprise pay rise as union pressure grows
Apple plans to give U.S. workers a pay rise in the face of growing pressure from unions that are emerging in some retail locations.

Don't carry around your new MacBook Air bare! Get a case!
Your MacBook Air is expensive — make sure you protect it with a case! We've rounded up the very best.