Security Flaw Allows Anyone to Reset Your Apple ID Password Using an Email Address and Birth Date
Yesterday Apple implemented an optional two-step verification system for Apple ID accounts, allowing users to set a dedicated device and use a recovery code to strengthen the security of Apple accounts. With two-step verification, it is impossible for people to access and manage your Apple ID without access to your password and a verification code sent to your “trusted” device.
If you haven’t yet activated two-step verification, your Apple ID could potentially be in jeopardy. The Verge is reporting that a new exploit has been discovered that allows anyone to reset the password of an iTunes account that does not use two-step verification.