Apple's Passwords App Had a Security Flaw That Exposed Users to Phishing Attacks for Three Months

Apple's revised release notes for the iOS 18.2 update reveal that it patched two issues related to its Passwords app.

Advertisement
Written by David Delima | Updated: 19 March 2025 15:30 IST
Highlights
  • Apple fixed two flaws with its Passwords app on iOS 18.2
  • iOS 18.1 rolled out to users in December 2024
  • Apple has updated its release notes to detail the security fixes

Apple introduced a standalone Passwords app on iOS 18

Photo Credit: Pexels/ Antoni Shkraba

Apple released a dedicated Passwords app last year, as part of the iOS 18 software update. Instead of a menu inside the Settings app, users can access their passwords and other details via a standalone app. However, the Passwords app had a serious security flaw that exposed users to potential phishing attacks from attackers who were on the same Wi-Fi network. The company recently disclosed that it fixed the security flaw three months after iOS 18 was released.

Apple Fixed Passwords App Vulnerability With iOS 18.2 Update

The iPhone maker recently amended its release notes (via 9to5Mac) for the iOS 18.2 update, which was released in December. The document now includes two entries, both titled 'Passwords', that describe fixes for the app. Apple has credited Mysk security researchers Talal Haj Bakry and Tommy Mysk with identifying the security vulnerability.

According to the company's updated support document, the first patch for the Passwords app on iOS 18.2 fixed two flaws that allowed a user in a privileged network position to leak sensitive information, and alter network traffic. 

Advertisement

The Mysk researchers discovered that Apple's Passwords app wasn't using encrypted connections (HTTPS) when fetching details of specific sites, such as site icons. Similarly, password reset pages were loaded over HTTP.

Advertisement

The same flaw would allow an attacker on the same Wi-Fi network to intercept the network request, and direct the device to load a phishing website instead of the legitimate one. If the user trusts the webpage, they might enter their credentials on the fraudulent website.

The cybersecurity firm reported the issue to Apple in September, and Apple's revised support document reveals that it rolled out fixes for the issue with iOS 18.2 in December. Eligible iPhone and iPad models that are running on iOS 18.2 and iPadOS 18.2 or newer versions should not be vulnerable to the flaw.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Son of Sardaar 2 OTT Release: Know When and Where to Watch it Online
  2. The Madras Mystery OTT Release: Know All About This Nazriya Nazim Thriller
  1. The Madras Mystery OTT Release: This Nazriya Nazim Thriller Will Soon Arrive on This Platform
  2. The Treasure Hunters OTT Release: Know When and Where to Watch Manisha Rani's Game Show Online
  3. Sarkeet OTT Release: This Is Where You Can Watch the Asif Ali-Starrer Later This Month
  4. Researchers Reconstruct 2,500-Year-Old Faces From Skulls Found in Tamil Nadu
  5. House Mates OTT Release: When and Where to Watch the Tamil Horror Comedy Online
  6. Black Hole Kicked Away? Gravitational Waves Reveal Einstein’s Ripples in Spacetime
  7. NASA’s Artemis II Astronauts Will Double as Test Subjects for Deep Space Health Research
  8. Canadian Startup Qubic Unveils Cryogenic Amplifier That Could Transform Quantum Computing
  9. Vembu Is Streaming Now on Aha Tamil: All You Need to Know About the Tamil Social Drama
  10. Son of Sardaar 2 OTT Release: Know When and Where to Watch the Ajay Devgn-Starrer Online
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.