• AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Apple Password App Security Flaw Exposed Users to Phishing for 3 Months

Akinola Ajibola by Akinola Ajibola
March 20, 2025
in Security
Share on FacebookShare on Twitter

As part of the iOS 18 software upgrade last year, Apple created a Passwords app specifically for the purpose. Users may access their passwords and other information using a stand-alone app rather than a menu within the Settings app. A significant security vulnerability in the Passwords app, however, left users vulnerable to possible phishing attempts by attackers connected to the same Wi-Fi network. Three months after the introduction of iOS 18, the firm just revealed that it has resolved the security vulnerability.

The corporation stated in a statement on its security website that “a user in a privileged network position may be able to leak sensitive information.” It claimed that utilizing HTTPS while transferring data across the network resolved the problem.

According to an Apple security content update discovered, the iOS 18.2 update was issued in December, and the iPhone manufacturer recently updated its release notes (via 9to5Mac). ‘Passwords’ is the title of two new items in the document that discuss app fixes. Apple attributes the discovery of the security flaw to Mysk security experts Tommy Mysk and Talal Haj Bakry which left users open to phishing assaults.

The Passwords app was making unencrypted requests for the symbols and emblems that appear next to the websites that your saved passwords are linked to, as 9to5Mac reports. Because there was no encryption, someone using the same Wi-Fi network as you, such as at a coffee shop or airport, may divert your browser to a fake phishing website and steal your login information. Security researchers at software developer Mysk made the first discovery.

The first patch for iOS 18.2’s Passwords app addressed two vulnerabilities that let a user with privileged network access change network traffic and disclose private data, according to the company’s revised support page.

The Mysk researchers observed that Apple’s Passwords app wasn’t using encrypted connections (HTTPS) when retrieving data of specific sites, such as site icons. In a similar manner, HTTP was used to load password reset sites.

An attacker on the same Wi-Fi network may use the same vulnerability to intercept the network request and instruct the device to load a phishing webpage rather than the authentic one. The user may input their credentials on the phony website if they have faith in the website.

According to Apple’s updated support page, the cybersecurity firm informed the company about the problem in September, and in December, the company released remedies for iOS 18.2. It should not be a problem for eligible iPhone and iPad devices running iOS 18.2 and iPadOS 18.2 or later.

Apple explains the flaw and its solution as follows: Impact: Sensitive information might be leaked by a user with privileged network access. This problem was fixed by utilizing HTTPS when transmitting data over the network.

ABI Research security analyst Georgia Cooke described the problem as “not a small-fry bug.”

Cooke remarked, “It’s a hell of a slip from Apple, really,” “For the user, this is a concerning vulnerability demonstrating failure in basic security protocols, exposing them to a long-standing attack form which requires limited sophistication.” 

Since it needs a rather particular combination of conditions, such as selecting to change your login from a password manager, doing so on a public network, and not realizing whether you’re being rerouted, Cooke says most users probably won’t encounter this problem. Nevertheless, it serves as a helpful reminder of the significance of routinely updating your equipment.

People may take additional precautions to guard against these types of vulnerabilities, particularly on shared networks, she noted. This includes avoiding critical transactions like changing credentials on public Wi-Fi, reusing passwords, and directing device traffic through a virtual private network.

Related Posts:

  • passkey-sync
    Google Begins Rollout Of Passkeys Across Its Services
  • key-visual2
    Google Password-less Sign-in Standard Introduces…
  • Microsoft Unveils New Surface Laptop
    Microsoft Plans Password Deletion for 1 Billion Users
  • 020tYFWBL4Yz8jIIFUdKDR1-22
    A Fix to Microsoft Windows Defender And Security Flaws
  • WhatsApp Password Feature (1)
    WhatsApp Adds Password Feature for Stronger Account Security
  • substack-data-breach-exposes
    Substack Breach Exposes User Emails, Phone Numbers
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…
  • was-ist-cpanel
    Hackers Are Exploiting Critical cPanel Bug, Putting…

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: Appleapple Passwordscybersecurity
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Meta Acquires Robotics Startup To Boost & Improve Its Humanoid AI Efforts May 2, 2026
  • xAI Rolls out Grok 4.3 and a New Voice Cloning Suite May 2, 2026
  • Pentagon Taps Nvidia, Microsoft And AWS To Bring AI To Classified Networks May 1, 2026
  • Hackers Are Exploiting Critical cPanel Bug, Putting Millions of Websites at Risk May 1, 2026
  • Alibaba’s Metis Agent Aims to Fix ‘Trigger‑Happy’ AI Tool Use With New RL Framework May 1, 2026
  • Samsung Q1 2026 Earnings: Record Profit Driven by AI Memory Chip Boom May 1, 2026
  • Qualcomm Q1 2026 Earnings: China Weakness and AI Push Drive Mixed Results May 1, 2026
  • Amazon Q1 2026 Earnings: AWS and AI Drive Strong Growth Despite Spending Concerns May 1, 2026
  • Meta Q1 2026 Earnings: Strong Revenue Growth Overshadowed by Massive AI Spending May 1, 2026
  • Apple Q2 2026 Earnings: $111B Revenue, iPhone 17 Drives Record Growth May 1, 2026
  • IBM Rolls out ‘Bob’, an AI Development Partner Built around Multi-model Routing and Human Checkpoints April 29, 2026
  • iOS 27 Reportedly Adds New Apple Intelligence Photo Editing Tools April 29, 2026

Browse Archives

May 2026
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Apr    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

Chat with TechBooky AI
💬
TechBooky AI ✕
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.