Apple's Passwords App Had a Security Flaw That Exposed Users to Phishing Attacks for Three Months

Apple's revised release notes for the iOS 18.2 update reveal that it patched two issues related to its Passwords app.

Advertisement
Written by David Delima | Updated: 19 March 2025 15:30 IST
Highlights
  • Apple fixed two flaws with its Passwords app on iOS 18.2
  • iOS 18.1 rolled out to users in December 2024
  • Apple has updated its release notes to detail the security fixes

Apple introduced a standalone Passwords app on iOS 18

Photo Credit: Pexels/ Antoni Shkraba

Apple released a dedicated Passwords app last year, as part of the iOS 18 software update. Instead of a menu inside the Settings app, users can access their passwords and other details via a standalone app. However, the Passwords app had a serious security flaw that exposed users to potential phishing attacks from attackers who were on the same Wi-Fi network. The company recently disclosed that it fixed the security flaw three months after iOS 18 was released.

Apple Fixed Passwords App Vulnerability With iOS 18.2 Update

The iPhone maker recently amended its release notes (via 9to5Mac) for the iOS 18.2 update, which was released in December. The document now includes two entries, both titled 'Passwords', that describe fixes for the app. Apple has credited Mysk security researchers Talal Haj Bakry and Tommy Mysk with identifying the security vulnerability.

According to the company's updated support document, the first patch for the Passwords app on iOS 18.2 fixed two flaws that allowed a user in a privileged network position to leak sensitive information, and alter network traffic. 

Advertisement

The Mysk researchers discovered that Apple's Passwords app wasn't using encrypted connections (HTTPS) when fetching details of specific sites, such as site icons. Similarly, password reset pages were loaded over HTTP.

Advertisement

The same flaw would allow an attacker on the same Wi-Fi network to intercept the network request, and direct the device to load a phishing website instead of the legitimate one. If the user trusts the webpage, they might enter their credentials on the fraudulent website.

The cybersecurity firm reported the issue to Apple in September, and Apple's revised support document reveals that it rolled out fixes for the issue with iOS 18.2 in December. Eligible iPhone and iPad models that are running on iOS 18.2 and iPadOS 18.2 or newer versions should not be vulnerable to the flaw.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  2. Lenovo Idea Tab Plus Launched in India With 10,200mah Battery: Details
  3. Redmi Note 15 5G Chipset Revealed Ahead of January 6 India Launch
  4. Mrs Deshpande OTT Release Date: Madhuri Dixit's Starrere to Premiere on This Date
  5. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  6. Vivo S50, S50 Pro Mini With Snapdragon Chips Launched at These Prices
  7. Motorola Edge 70 With 5,000mAh Battery Launched in India at This Price
  8. MacBook Air (2025) With M4 Chip Available at This Discounted Price
  9. Motorola Edge 70 First Impressions
  10. RAM Crisis 2026: 16GB Phones Out, 4GB Models Making a Comeback
  1. Webb Telescope Discovers Hidden Atmosphere on Molten Super-Earth TOI-561 b Despite Extreme Heat
  2. Astronomers Watch a Dormant Neutron Star Reignite After a Decade of Silence
  3. Predictive Forecasting Tools Can Boost the Success of Clean Energy Investments Worldwide
  4. Chinese Spacecraft Nearly Slammed Into Starlink Satellite, SpaceX Reveals
  5. Clocks on Mars Run Faster Than on Earth, New Study Finds
  6. The Hunting Wives Out on OTT: Know Everything About This American Thriller Mystery Series
  7. All Her Fault Now Streaming on JioHotstar: Know Everything About This Thriller Series
  8. Wednesday Season 3 Set for July 2027 on Netflix: Jenna Ortega Returns as the Iconic Addams Heir
  9. Lakshmi Manchu’s Daksha: The Deadly Conspiracy Available for Streaming on Amazon Prime Video
  10. Posthouse Now Available to Stream on Netflix: Know Everything About This Psychological Thriller Film
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.