A worrying Apple Password App vulnerability reportedlyleft users exposed for months


- Apple’s Password App has been patched after a vulnerability was discovered
- The flaw left users exposed for three months, experts claim
- Users were at risk of social engineering attacks
A bug in the iOS 18.2 Passwords app which left users vulnerable to phishing attacks for over three months after its release, has been fixed, according to an update from Apple.
The flaw was discovered after security researchers at Mysk noticed that their device’s App Privacy Report showed the Passwords App had contacted 130 different websites over insecure HTTP traffic.
The app used the HTTP protocol instead of a more secure HTTPS when opening links and downloading app icons. Upon further investigation, the researchers found that the app also defaulted to opening password reset pages with the unencrypted protocol. This left users vulnerable as an attacker “privileged network access could intercept the HTTP request and redirect the user to a phishing website,” the researchers told 9to5Mac.
You may like
Patch now
The risk in this attack is that cybercriminals will use the vulnerability to carry out social engineering attacks by redirecting victims to insecure websites.
The Password app will now use HTTPS for all connections by default – so ensure your Apple devices are all updated and using iOS 18.2 or later.
Research has shown security attacks on password managers have soared in recent months, with reports finding a threefold increase in malware that targets credentials in password stores.
The attacks are also growing in sophistication , with cybercriminals prioritizing “complex, prolonged, multi-stage attacks” delivered with an all-new generation of malware. This new malware, like infostealers, comes with more persistence, stealth, and automation.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The best, and most secure, password manager tools will safely store, generate, and crucially autofill your website and app passwords. These can help you create and manage your unique and strong passwords without the hassle of having to remember each one.
You might also like
Apple’s Password App has been patched after a vulnerability was discovered The flaw left users exposed for three months, experts claim Users were at risk of social engineering attacks A bug in the iOS 18.2 Passwords app which left users vulnerable to phishing attacks for over three months after its…
Recent Posts
- Not Just Any Prime Day Deals, 255 Obsessively Tested Picks—Even $1,200 Off an OLED TV
- Why the AI boom requires an Wyatt Earp
- The four-phase security approach to keep in mind for your AI transformation
- Musk makes grand promises about Grok 4 in the wake of a Nazi chatbot meltdown
- Tempur-Pedic Promo Codes: Up to 50% Off
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022