'okay, so this is really Apple'
2025-01-08 20:28:44.56897+01 by Dan Lyke 0 comments
Account security gets harder:
If you're an Apple user and I spoof your phone number in a call to the legitimate Apple Customer Support line (800-275-2273), I can force Apple to send you a system level "Apple Account Confirmation" prompt to all of your signed-in devices.
Which means that a phishing operation has a fairly credible pathway in which to convince you that they're Apple from a phone call... That they initiated, true, but still, it's a vector.