A worrying Apple Password App vulnerability reportedlyleft users exposed for months
- Apple’s Password App has been patched after a vulnerability was discovered
- The flaw left users exposed for three months, experts claim
- Users were at risk of social engineering attacks
A bug in the iOS 18.2 Passwords app which left users vulnerable to phishing attacks for over three months after its release, has been fixed, according to an update from Apple.
The flaw was discovered after security researchers at Mysk noticed that their device’s App Privacy Report showed the Passwords App had contacted 130 different websites over insecure HTTP traffic.
The app used the HTTP protocol instead of a more secure HTTPS when opening links and downloading app icons. Upon further investigation, the researchers found that the app also defaulted to opening password reset pages with the unencrypted protocol. This left users vulnerable as an attacker “privileged network access could intercept the HTTP request and redirect the user to a phishing website,” the researchers told 9to5Mac.
You may like
Patch now
The risk in this attack is that cybercriminals will use the vulnerability to carry out social engineering attacks by redirecting victims to insecure websites.
The Password app will now use HTTPS for all connections by default – so ensure your Apple devices are all updated and using iOS 18.2 or later.
Research has shown security attacks on password managers have soared in recent months, with reports finding a threefold increase in malware that targets credentials in password stores.
The attacks are also growing in sophistication , with cybercriminals prioritizing “complex, prolonged, multi-stage attacks” delivered with an all-new generation of malware. This new malware, like infostealers, comes with more persistence, stealth, and automation.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The best, and most secure, password manager tools will safely store, generate, and crucially autofill your website and app passwords. These can help you create and manage your unique and strong passwords without the hassle of having to remember each one.
You might also like
Apple’s Password App has been patched after a vulnerability was discovered The flaw left users exposed for three months, experts claim Users were at risk of social engineering attacks A bug in the iOS 18.2 Passwords app which left users vulnerable to phishing attacks for over three months after its…
Recent Posts
- If Vampire Survivors and Spelunky had a baby, it’d be Messhof’s Blood Dungeon
- Grand Theft Auto VI is warping the video game release calendar
- 9 dog-care gadgets that are so clever they deserve a treat — including an ingenious on-the-go water solution and a ‘canine FitBit’
- Control Resonant is a sequel — and also a starting point
- Summer Game Fest Live 2026: The biggest news, trailers, and announcements
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023