Apple's Passwords App Had a Security Flaw That Exposed Users to Phishing Attacks for Three Months

Apple's revised release notes for the iOS 18.2 update reveal that it patched two issues related to its Passwords app.

Advertisement
Written by David Delima | Updated: 19 March 2025 15:30 IST
Highlights
  • Apple fixed two flaws with its Passwords app on iOS 18.2
  • iOS 18.1 rolled out to users in December 2024
  • Apple has updated its release notes to detail the security fixes

Apple introduced a standalone Passwords app on iOS 18

Photo Credit: Pexels/ Antoni Shkraba

Apple released a dedicated Passwords app last year, as part of the iOS 18 software update. Instead of a menu inside the Settings app, users can access their passwords and other details via a standalone app. However, the Passwords app had a serious security flaw that exposed users to potential phishing attacks from attackers who were on the same Wi-Fi network. The company recently disclosed that it fixed the security flaw three months after iOS 18 was released.

Apple Fixed Passwords App Vulnerability With iOS 18.2 Update

The iPhone maker recently amended its release notes (via 9to5Mac) for the iOS 18.2 update, which was released in December. The document now includes two entries, both titled 'Passwords', that describe fixes for the app. Apple has credited Mysk security researchers Talal Haj Bakry and Tommy Mysk with identifying the security vulnerability.

According to the company's updated support document, the first patch for the Passwords app on iOS 18.2 fixed two flaws that allowed a user in a privileged network position to leak sensitive information, and alter network traffic. 

Advertisement

The Mysk researchers discovered that Apple's Passwords app wasn't using encrypted connections (HTTPS) when fetching details of specific sites, such as site icons. Similarly, password reset pages were loaded over HTTP.

Advertisement

The same flaw would allow an attacker on the same Wi-Fi network to intercept the network request, and direct the device to load a phishing website instead of the legitimate one. If the user trusts the webpage, they might enter their credentials on the fraudulent website.

The cybersecurity firm reported the issue to Apple in September, and Apple's revised support document reveals that it rolled out fixes for the issue with iOS 18.2 in December. Eligible iPhone and iPad models that are running on iOS 18.2 and iPadOS 18.2 or newer versions should not be vulnerable to the flaw.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15T Details Revealed; New Telephoto Lens, Bigger Battery Confirmed
  2. iPad Air (2026) With M4 Chip Launched in India at This Price
  3. iQOO Z11x 5G Will Launch in India on This Date
  4. iPhone 17e vs iPhone 16e: Price, Features and Specifications Compared
  5. iPhone 17e Launched in India With MagSafe, 48-Megapixel Camera: See Price
  6. Here's When the Oppo K14 5G Will Launch in India: See Expected Specs
  7. Here's When the Oppo Find X9 Ultra Will Be Launched Globally
  8. Nothing Phone 4a Will Go on Sale in Bengaluru at a Drop Event on This Date
  9. Xiaomi 18 Series Leak Suggests Major Camera Upgrades Over Predecessor
  10. MWC 2026: Tecno Camon 50 Ultra 5G Unveiled With a 6,500mAh Battery
  1. Tanvi The Great Now Streaming on Prime Video: An Inspiring Autistic Hero’s Journey
  2. Aspirants Season 3 OTT Release Date Announced: When and Where to Watch it Online?
  3. Samsung Announces ‘Holi Hai’ Sale With Cashback on Bespoke AI Appliances
  4. Kiss of the Spider Woman OTT Release Date: Know When and Where to Watch it Online
  5. Vanchana OTT Release: When and Where to Watch the Courtroom Drama
  6. Xiaomi 18, Xiaomi 18 Pro, Xiaomi 18 Pro Max Early Leak Reveals Rear Camera Details
  7. Meta AI Reportedly Testing Personalised Shopping Recommendations to Compete With ChatGPT, Gemini
  8. Oppo Find N6 Reportedly Appears at MWC 2026; Company Confirms March Launch in China
  9. Resident Evil Requiem Becomes Highest User Rated Game of All Time on Metacritic
  10. MWC 2026: Tecno Camon 50 Ultra 5G Unveiled With 6,500mAh Battery, 50–Megapixel Camera
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.