Apple's Passwords App Had a Security Flaw That Exposed Users to Phishing Attacks for Three Months

Apple's revised release notes for the iOS 18.2 update reveal that it patched two issues related to its Passwords app.

Advertisement
Written by David Delima | Updated: 19 March 2025 15:30 IST
Highlights
  • Apple fixed two flaws with its Passwords app on iOS 18.2
  • iOS 18.1 rolled out to users in December 2024
  • Apple has updated its release notes to detail the security fixes

Apple introduced a standalone Passwords app on iOS 18

Photo Credit: Pexels/ Antoni Shkraba

Apple released a dedicated Passwords app last year, as part of the iOS 18 software update. Instead of a menu inside the Settings app, users can access their passwords and other details via a standalone app. However, the Passwords app had a serious security flaw that exposed users to potential phishing attacks from attackers who were on the same Wi-Fi network. The company recently disclosed that it fixed the security flaw three months after iOS 18 was released.

Apple Fixed Passwords App Vulnerability With iOS 18.2 Update

The iPhone maker recently amended its release notes (via 9to5Mac) for the iOS 18.2 update, which was released in December. The document now includes two entries, both titled 'Passwords', that describe fixes for the app. Apple has credited Mysk security researchers Talal Haj Bakry and Tommy Mysk with identifying the security vulnerability.

According to the company's updated support document, the first patch for the Passwords app on iOS 18.2 fixed two flaws that allowed a user in a privileged network position to leak sensitive information, and alter network traffic. 

Advertisement

The Mysk researchers discovered that Apple's Passwords app wasn't using encrypted connections (HTTPS) when fetching details of specific sites, such as site icons. Similarly, password reset pages were loaded over HTTP.

The same flaw would allow an attacker on the same Wi-Fi network to intercept the network request, and direct the device to load a phishing website instead of the legitimate one. If the user trusts the webpage, they might enter their credentials on the fraudulent website.

The cybersecurity firm reported the issue to Apple in September, and Apple's revised support document reveals that it rolled out fixes for the issue with iOS 18.2 in December. Eligible iPhone and iPad models that are running on iOS 18.2 and iPadOS 18.2 or newer versions should not be vulnerable to the flaw.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Vivo X200T Could Cost in India: See Expected Specs
  2. Amazon Great Republic Day Sale: Top Deals on Smartwatches Under Rs. 10,000
  3. Top Deals on Phones Under Rs. 50,000 During Amazon's Republic Day Sale
  4. Amazon Great Republic Day Sale Is Live: Best Offers Today
  5. Lava Blaze Duo 3 to Launch in India on This Date
  6. Top Deals on OnePlus Smartphones During the Amazon Great Republic Day Sale
  7. Amazon Great Republic Day Sale: Top Laptop Deals Under Rs. 40,000
  8. India Becomes World's Second Largest 5G Base with 400M+ Users
  9. OnePlus 15T Launch Timeline, Chipset Details Leaked
  10. Honor Magic 8 RSR Porsche Design Teased to Come With a Photography Kit
  1. Hypothetical ‘Dark Stars’ Could Rewrite Early Cosmic History, Research Suggests
  2. Honor Magic 8 Pro Air Key Features Confirmed; Company Teases External Lens for Honor Magic 8 RSR Porsche Design
  3. Lava Blaze Duo 3 India Launch Date Announced; Colour Options Teased Ahead of Debut
  4. Resident Evil Requiem Gets New Leon Gameplay at Resident Evil Showcase
  5. After ChatGPT Translate, Google Releases Multiple Open-Source Translation Models
  6. Realme Buds Clip India Launch Timeline Confirmed: Expected Specifications, Features
  7. NASA's James Webb Space Telescope Might Have Spotted Hidden Supermassive Black Holes
  8. Tere Ishk Mein Reportedly Streams on OTT Soon: All You Need to Know About Dhanush and Kriti Sanon-Starrer
  9. Amazon Great Republic Day Sale: Top Laptop Deals Under Rs. 40,000
  10. OnePlus 15T Launch Timeline, Chipset Details Leaked: Expected Specifications, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.