Apple's Passwords App Had a Security Flaw That Exposed Users to Phishing Attacks for Three Months

Apple's revised release notes for the iOS 18.2 update reveal that it patched two issues related to its Passwords app.

Advertisement
Written by David Delima | Updated: 19 March 2025 15:30 IST
Highlights
  • Apple fixed two flaws with its Passwords app on iOS 18.2
  • iOS 18.1 rolled out to users in December 2024
  • Apple has updated its release notes to detail the security fixes

Apple introduced a standalone Passwords app on iOS 18

Photo Credit: Pexels/ Antoni Shkraba

Apple released a dedicated Passwords app last year, as part of the iOS 18 software update. Instead of a menu inside the Settings app, users can access their passwords and other details via a standalone app. However, the Passwords app had a serious security flaw that exposed users to potential phishing attacks from attackers who were on the same Wi-Fi network. The company recently disclosed that it fixed the security flaw three months after iOS 18 was released.

Apple Fixed Passwords App Vulnerability With iOS 18.2 Update

The iPhone maker recently amended its release notes (via 9to5Mac) for the iOS 18.2 update, which was released in December. The document now includes two entries, both titled 'Passwords', that describe fixes for the app. Apple has credited Mysk security researchers Talal Haj Bakry and Tommy Mysk with identifying the security vulnerability.

Advertisement

According to the company's updated support document, the first patch for the Passwords app on iOS 18.2 fixed two flaws that allowed a user in a privileged network position to leak sensitive information, and alter network traffic. 

The Mysk researchers discovered that Apple's Passwords app wasn't using encrypted connections (HTTPS) when fetching details of specific sites, such as site icons. Similarly, password reset pages were loaded over HTTP.

Advertisement

The same flaw would allow an attacker on the same Wi-Fi network to intercept the network request, and direct the device to load a phishing website instead of the legitimate one. If the user trusts the webpage, they might enter their credentials on the fraudulent website.

The cybersecurity firm reported the issue to Apple in September, and Apple's revised support document reveals that it rolled out fixes for the issue with iOS 18.2 in December. Eligible iPhone and iPad models that are running on iOS 18.2 and iPadOS 18.2 or newer versions should not be vulnerable to the flaw.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple Brings New Wallpaper, Apple Music Playlist Ahead of WWDC 2026
  2. Hisense Launches U7SE 144Hz ULED Mini-LED TV Series in India
  3. Sony Bravia 7II 4K TVs With Cognitive Processor XR Debut in India
  4. Nothing Ear 3a, CMF Buds Neo Visit Regulatory Databases, Might Launch Soon
  5. Samsung Galaxy Z Fold 8, Z Fold 8 Ultra Leaked Dummies Hint at These Designs
  6. New iPhone 18 Pro Leak Suggests It Could Arrive in These Battery Variants
  7. Apple's First Foldable iPhone May Get White Colourway, VC Cooling
  1. Nothing Ear 3a, CMF Buds Neo Spotted on Regulatory Databases Ahead of Anticipated Debut
  2. Samsung Galaxy Z Fold 8, Galaxy Z Fold 8 Ultra Could Feature Vastly Different Designs, Leaked Dummy Units Suggest
  3. Hisense U7SE 144Hz ULED Mini-LED TV Series With Up to 100-Inch Screens Launched in India: Price, Features
  4. Vivo Y500 Surfaces on Bluetooth SIG Database With Multiple Model Numbers, Could Launch Soon
  5. Asus Ascent QN10 Mini PC With Snapdragon X2 Elite Chipset Showcased at Computex 2026
  6. MSI Showcases New Katana, Venture Laptops and Crosshair A16 HX MLG Edition at Computex 2026
  7. Acer TravelMate P6 14 AI and P2 Spin 14 Unveiled, Acer TravelMate X2 15 and X2 14 Tag Along
  8. Sony Bravia 7II 4K TVs Launched in India With Cognitive Processor XR, Dolby Vision: Price, Features
  9. Asus TUF 16 (2026) Gaming Laptop Unveiled Alongside ExpertBook B5 Flip G2 (2026) at Computex 2026
  10. Asus Zenbook 14, Vivobook S14, Vivobook S16, Vivobook S14 Flip and Vivobook S16 Flip Launched at Computex 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.