Search

Apple's Passwords App Had a Security Flaw That Exposed Users to Phishing Attacks for Three Months

Apple's revised release notes for the iOS 18.2 update reveal that it patched two issues related to its Passwords app.

Advertisement
Highlights
  • Apple fixed two flaws with its Passwords app on iOS 18.2
  • iOS 18.1 rolled out to users in December 2024
  • Apple has updated its release notes to detail the security fixes
Apple's Passwords App Had a Security Flaw That Exposed Users to Phishing Attacks for Three Months

Apple introduced a standalone Passwords app on iOS 18

Photo Credit: Pexels/ Antoni Shkraba

Apple released a dedicated Passwords app last year, as part of the iOS 18 software update. Instead of a menu inside the Settings app, users can access their passwords and other details via a standalone app. However, the Passwords app had a serious security flaw that exposed users to potential phishing attacks from attackers who were on the same Wi-Fi network. The company recently disclosed that it fixed the security flaw three months after iOS 18 was released.

Apple Fixed Passwords App Vulnerability With iOS 18.2 Update

The iPhone maker recently amended its release notes (via 9to5Mac) for the iOS 18.2 update, which was released in December. The document now includes two entries, both titled 'Passwords', that describe fixes for the app. Apple has credited Mysk security researchers Talal Haj Bakry and Tommy Mysk with identifying the security vulnerability.

According to the company's updated support document, the first patch for the Passwords app on iOS 18.2 fixed two flaws that allowed a user in a privileged network position to leak sensitive information, and alter network traffic. 

The Mysk researchers discovered that Apple's Passwords app wasn't using encrypted connections (HTTPS) when fetching details of specific sites, such as site icons. Similarly, password reset pages were loaded over HTTP.

The same flaw would allow an attacker on the same Wi-Fi network to intercept the network request, and direct the device to load a phishing website instead of the legitimate one. If the user trusts the webpage, they might enter their credentials on the fraudulent website.

The cybersecurity firm reported the issue to Apple in September, and Apple's revised support document reveals that it rolled out fixes for the issue with iOS 18.2 in December. Eligible iPhone and iPad models that are running on iOS 18.2 and iPadOS 18.2 or newer versions should not be vulnerable to the flaw.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo Y19e With 5,500mAh Battery Launched in India: Price, Offers
  2. Huawei Pura X Foldable Phone With 6.3-Inch 16:10 Inner Display Launched
  3. Oppo F29 5G, Oppo F29 Pro 5G Launched in India: Price, Features
  4. iPhone 17 Air Case Leak Hints at Pixel-Like Rear Camera Design
  5. HMD Barbie Phone With 2.8-Inch Display, Themed Accessories Launched in India
  6. CMF Phone 2 Alleged Hands-on Renders Suggest Upgraded Rear Camera Setup
  7. Realme Buds T200 Lite With Up to 48-Hour Total Battery Life Launched in India
  8. Infinix Note 50X 5G Battery, Charging Details Revealed; Price Range Tipped
  1. Brahma Anandam Now Streaming on Aha: Everything You Need to Know
  2. A Complete Unknown OTT Release Date: When and Where to Watch Timothée Chalamet’s Biopic
  3. Touch Me Not Telugu OTT Release Date: When and Where to Watch it Online?
  4. Sabdham OTT Release Date: When and Where to Watch Aadhi Pinisetty’s Horror Thriller
  5. Wolf-Rayet 104's Orbit Tilt Reduces Gamma-Ray Burst Threat, Study Finds
  6. Mount Spurr Volcano in Alaska Shows Signs of Possible Eruption
  7. Iguanas Travelled 5,000 Miles to Fiji on Rafts 34 Million Years Ago
  8. Atacama Telescope Reveals Most Detailed Cosmic Microwave Background Yet
  9. NASA, SpaceX Crew-9 Returns on Crew Dragon Freedom After 171 Days in Space
  10. Rocket Lab Launches Final Five Satellites for Kinéis' IoT Constellation
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »