Earlier quoted context omitted.
This seems very much like Apple’s bug, to the extent that they paid out a $100k bug bounty?
Really? > ...affected third-party applications which were using it and didn’t implement their own additional security measures.
> I found I could request JWTs for any Email ID from Apple and when the signature of these tokens was verified using Apple’s public key, they showed as valid. This means an attacker could forge a JWT by linking any Email ID to it and gaining access to the victim’s account.