Apple's Passwords App Had a Security Flaw That Exposed Users to Phishing Attacks for Three Months

Apple's revised release notes for the iOS 18.2 update reveal that it patched two issues related to its Passwords app.

Advertisement
Written by David Delima | Updated: 19 March 2025 15:30 IST
Highlights
  • Apple fixed two flaws with its Passwords app on iOS 18.2
  • iOS 18.1 rolled out to users in December 2024
  • Apple has updated its release notes to detail the security fixes

Apple introduced a standalone Passwords app on iOS 18

Photo Credit: Pexels/ Antoni Shkraba

Apple released a dedicated Passwords app last year, as part of the iOS 18 software update. Instead of a menu inside the Settings app, users can access their passwords and other details via a standalone app. However, the Passwords app had a serious security flaw that exposed users to potential phishing attacks from attackers who were on the same Wi-Fi network. The company recently disclosed that it fixed the security flaw three months after iOS 18 was released.

Apple Fixed Passwords App Vulnerability With iOS 18.2 Update

The iPhone maker recently amended its release notes (via 9to5Mac) for the iOS 18.2 update, which was released in December. The document now includes two entries, both titled 'Passwords', that describe fixes for the app. Apple has credited Mysk security researchers Talal Haj Bakry and Tommy Mysk with identifying the security vulnerability.

According to the company's updated support document, the first patch for the Passwords app on iOS 18.2 fixed two flaws that allowed a user in a privileged network position to leak sensitive information, and alter network traffic. 

Advertisement

The Mysk researchers discovered that Apple's Passwords app wasn't using encrypted connections (HTTPS) when fetching details of specific sites, such as site icons. Similarly, password reset pages were loaded over HTTP.

Advertisement

The same flaw would allow an attacker on the same Wi-Fi network to intercept the network request, and direct the device to load a phishing website instead of the legitimate one. If the user trusts the webpage, they might enter their credentials on the fraudulent website.

The cybersecurity firm reported the issue to Apple in September, and Apple's revised support document reveals that it rolled out fixes for the issue with iOS 18.2 in December. Eligible iPhone and iPad models that are running on iOS 18.2 and iPadOS 18.2 or newer versions should not be vulnerable to the flaw.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Series Confirmed to Be Available in India via Flipkart
  2. Vivo X300 Series Price, Key Features Leaked Ahead of Global Launch
  3. Nothing Phone 3a Lite Launched With Glyph Light At This Price
  4. Google's Latest AI Models Will Now Be Available Directly via Adobe Apps
  5. Moto G67 Power 5G India Launch Date, Key Features Announced
  6. Amazon Fire TV Stick 4K Select Launched in India With Vega OS
  7. TRAI, DoT Approve Presentation of Caller Names During Incoming Calls
  1. NASA’s X-59 Supersonic Jet Takes Historic First Flight, Paving Way for Quiet Supersonic Travel
  2. ASIC Clarifies Crypto Rules; Stablecoins, Tokenised Assets Flagged as Financial Products
  3. SpaceX Launches 28 Starlink Satellites, Lands Falcon 9 Booster in Pacific
  4. Idli Kadai, Starring Dhanush, Now Streaming on Netflix: What You Need to Know
  5. Ideabaaz Now Streaming on ZEE5: Everything You Need to Know
  6. Grey’s Anatomy Season 22 OTT Release: Know Where to Watch it Online?
  7. Bad Girl OTT Release Date: When and Where to Watch Tamil Drama Online?
  8. Adobe Partners With Google Cloud to Integrate Frontier AI Models Across Its Platforms
  9. Vivo X300, Vivo X300 Pro Price and Key Specifications Leaked Ahead of Global Launch
  10. OnePlus 15 India Launch Date Announced; to Debut as First Snapdragon 8 Elite Gen 5 Phone in India
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.