Fetching from the wire…
Public story · 2026-08-24 · high
The flaw let a client-supplied email bind a new Apple sign-in to someone else's account, and v0.2.2 removes that field entirely.
Why now: Cumora tagged the v0.2.2 release carrying this fix on August 24, 2026.
Cumora patched a bug in its Apple sign-in flow that let a client-supplied email address link a new Apple identity to someone else's existing account. Anyone who could set that field in the request could point their Apple sign-in at somebody else's account without any server-side check.
The native endpoint took the email straight from the request body and fell back to it whenever Apple's signed token carried none. That fallback value was enough to bind the new Apple identity to an account under a different login.
Cumora's v0.2.2 release removes the email field from the request contract entirely. There's no more client-supplied value to fall back to. For an Apple sub that isn't already linked, the app now requires an email_verified claim inside Apple's own token. Without that claim, it won't trust the address.
The release notes don't say how long the field sat in the request contract, or whether Cumora found it through review or a report. They don't say whether any accounts were linked this way before the patch.
Each link below shares sources, entities, or timing with this story.
Apple supports Claude / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (Apple supports Claude); both cover Apple, GitHub; reported by the same outlet (github.com).
Cumora supports Claude Code / Shared entity: GitHub / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Cumora supports Claude Code); both cover GitHub; reported by the same outlet (github.com).
Apple partners with Alibaba / Shared entity: GitHub / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Apple partners with Alibaba); both cover GitHub; reported by the same outlet (github.com).
Apple uses Gemini / Shared entity: GitHub / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Apple uses Gemini); both cover GitHub; reported by the same outlet (github.com).
Cumora supports Claude Code / Shared entity: GitHub / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Cumora supports Claude Code); both cover GitHub; reported by the same outlet (github.com).
Apple criticizes OpenAI / Shared entity: GitHub / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Apple criticizes OpenAI); both cover GitHub; reported by the same outlet (github.com).
Cumora supports Claude Code / Shared entity: GitHub / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Cumora supports Claude Code); both cover GitHub; reported by the same outlet (github.com).
Cumora supports Codex / Shared entity: GitHub / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Cumora supports Codex); both cover GitHub; reported by the same outlet (github.com).