iOS Users Can Be Easily Tricked Into Revealing Their Apple ID Password: Report

Advertisement
By Gadgets 360 Staff | Updated: 11 October 2017 11:44 IST
Highlights
  • There is a potential design flaw in iOS
  • The system-level password dialog box can be easily replicated by an app
  • Apple hasn't addressed the matter yet

There is a potential design flaw in iOS, Apple's mobile operating system, that allows any developer to recreate a genuine-looking password pop-up menu in their apps, as per s security researcher. The problem? iOS users are accustomed to seeing that pop-up menu at random times, a fact that a rogue developer could abuse. Since there is no way to tell the password dialog created by an app from the system-level pop-up, a user can easily be tricked into sharing their most sensitive information with the fraudulent agent thanks to the spoofing.

The flaw, which has existed for years, was spotted by Felix Krause, an iOS developer. According to Krause, it is very easy to replicate the dialog box. On its part, Apple has over the years done a poor job with how it asks users to interact with the dialog box. Users are used to seeing the box at random hours and entering their details, he said.

Advertisement

Spot the difference. There isn't one.
Photo Credit: Felix Krause

Advertisement

There is no evidence that a developer has ever tried to abuse this flaw, but one can't really tell even if it has happened. The only company that may have some information is Apple, which as usual remains tightlipped. "It is concerning to think that is all it would take to display a convincing dialog," Will Strafach, an iOS hacker and developer, tweeted.

"It's long past time that Apple removes the random password popups that plague iOS. They're a security flaw that should not exist in 2017," Marco Arment, a prominent iOS developer tweeted. "I'm sure whoever's responsible for them has some reasons they think are good for why they need to be there. They're not, and they don't."

Advertisement

As we wait for Apple to do something, Krause has found a stopgap solution that users can use to know when the password dialog they are seeing is genuine. Hit the home button. If it's a system-level dialog, it will stick around. If it's generated by an app, it would go away.

Additionally, "always close the dialog, and open the iCloud settings manually, and only enter [the password] there," Krause said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: iOS, Security, Mobiles, Apple
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy Watch Ultra 2, Watch 9 Visit China's 3C Ahead of Launch
  2. Vivo Y31s Launched in Malaysia With These Features
  3. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  4. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  5. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  6. WhatsApp Users on iOS Are Finally Getting Access to This Useful Feature
  7. How to Watch WWDC 2026 Live on YouTube, Apple TV, and More
  8. iQOO Neo 12 Tipped to Offer Major Display Upgrade Over Predecessor
  9. Samsung Galaxy S26 FE Design, Key Charging Detail Surfaces via Database
  10. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  1. WWDC 2026: Apple Launches macOS 27 Golden Gate With Major Siri Redesign and New AI Tools
  2. Astrophotographer Captures Giant Human-Shaped Solar Prominence
  3. Samsung Galaxy S26 FE Said to Ditch Matte Finish for a Glossy Rear Panel
  4. OnePlus N Series Tipped to Launch in India Next Month, Could Be More Affordable Than the OnePlus Nord CE 6 Lite
  5. Vivo Y31s 5G Launched With Snapdragon 4 Gen 2 Chip, 6,500mAh Battery: Price, Specifications
  6. Chinese Court Classifies Bitcoin as Property in Case Involving 107 BTC Theft
  7. Resident Evil Veronica Revealed at Summer Game Fest; Launch Set for 2027
  8. Karuppu OTT Release: When and Where to Watch Suriya’s Fantasy Action Drama Online
  9. iQOO Neo 12 Said to Bring Major Display Upgrade With Up to 185Hz Refresh Rate
  10. Samsung Galaxy Watch Ultra 2, Galaxy Watch 9 Clear Key Regulatory Hurdle Ahead of Anticipated Launch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.