The method is called “Session Fixation Attack” and basically comes down to using a previous browser session to extract private data and get access to an Apple ID.
This means that iTunes and App Store accounts can be compromised, as the hacker can change both the password and the email address.
Source