• Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Home Security

Apple Password App Security Flaw Exposed Users to Phishing for 3 Months

Akinola Ajibola by Akinola Ajibola
March 20, 2025
in Security
Share on FacebookShare on Twitter

As part of the iOS 18 software upgrade last year, Apple created a Passwords app specifically for the purpose. Users may access their passwords and other information using a stand-alone app rather than a menu within the Settings app. A significant security vulnerability in the Passwords app, however, left users vulnerable to possible phishing attempts by attackers connected to the same Wi-Fi network. Three months after the introduction of iOS 18, the firm just revealed that it has resolved the security vulnerability.

The corporation stated in a statement on its security website that “a user in a privileged network position may be able to leak sensitive information.” It claimed that utilizing HTTPS while transferring data across the network resolved the problem.

According to an Apple security content update discovered, the iOS 18.2 update was issued in December, and the iPhone manufacturer recently updated its release notes (via 9to5Mac). ‘Passwords’ is the title of two new items in the document that discuss app fixes. Apple attributes the discovery of the security flaw to Mysk security experts Tommy Mysk and Talal Haj Bakry which left users open to phishing assaults.

The Passwords app was making unencrypted requests for the symbols and emblems that appear next to the websites that your saved passwords are linked to, as 9to5Mac reports. Because there was no encryption, someone using the same Wi-Fi network as you, such as at a coffee shop or airport, may divert your browser to a fake phishing website and steal your login information. Security researchers at software developer Mysk made the first discovery.

The first patch for iOS 18.2’s Passwords app addressed two vulnerabilities that let a user with privileged network access change network traffic and disclose private data, according to the company’s revised support page.

The Mysk researchers observed that Apple’s Passwords app wasn’t using encrypted connections (HTTPS) when retrieving data of specific sites, such as site icons. In a similar manner, HTTP was used to load password reset sites.

An attacker on the same Wi-Fi network may use the same vulnerability to intercept the network request and instruct the device to load a phishing webpage rather than the authentic one. The user may input their credentials on the phony website if they have faith in the website.

According to Apple’s updated support page, the cybersecurity firm informed the company about the problem in September, and in December, the company released remedies for iOS 18.2. It should not be a problem for eligible iPhone and iPad devices running iOS 18.2 and iPadOS 18.2 or later.

Apple explains the flaw and its solution as follows: Impact: Sensitive information might be leaked by a user with privileged network access. This problem was fixed by utilizing HTTPS when transmitting data over the network.

ABI Research security analyst Georgia Cooke described the problem as “not a small-fry bug.”

Cooke remarked, “It’s a hell of a slip from Apple, really,” “For the user, this is a concerning vulnerability demonstrating failure in basic security protocols, exposing them to a long-standing attack form which requires limited sophistication.” 

Since it needs a rather particular combination of conditions, such as selecting to change your login from a password manager, doing so on a public network, and not realizing whether you’re being rerouted, Cooke says most users probably won’t encounter this problem. Nevertheless, it serves as a helpful reminder of the significance of routinely updating your equipment.

People may take additional precautions to guard against these types of vulnerabilities, particularly on shared networks, she noted. This includes avoiding critical transactions like changing credentials on public Wi-Fi, reusing passwords, and directing device traffic through a virtual private network.

Related Posts:

  • passkey-sync
    Google Begins Rollout Of Passkeys Across Its Services
  • key-visual2
    Google Password-less Sign-in Standard Introduces…
  • 020tYFWBL4Yz8jIIFUdKDR1-22
    A Fix to Microsoft Windows Defender And Security Flaws
  • Microsoft Unveils New Surface Laptop
    Microsoft Plans Password Deletion for 1 Billion Users
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…
  • csm_1200x630wa_5026e9630c
    Microsoft Pushes Edge & Disables Authenticator Autofill
  • Small-Business-Scale-In-Nigeria
    Small Businesses In Nigeria Are Still In Danger,…
  • A computer popup box screen warning of a system being hacked, compromised software environment. 3D illustration.
    Biggest Data Breaches Caused By Security Misconfigurations

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: Appleapple Passwordscybersecurity
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Select Category

    Receive top tech news directly in your inbox

    subscription from
    Loading

    Freshly Squeezed

    • AI Helps Google One Reach 150 Million Subscribers May 16, 2025
    • FT Lists Paymenow, TymeBank & Omnisient Among Africa’s Fastest-Growing Firms May 16, 2025
    • MoonPay and Mastercard Partner to Advance Stablecoin Payments May 16, 2025
    • Google Gemini Advanced Users Can Now Link to GitHub May 16, 2025
    • TikTok Accused of Violating EU Internet Content Rules May 15, 2025
    • Activists and Users Criticize NCC & Telcos Over Customer Penalties May 15, 2025

    Browse Archives

    May 2025
    MTWTFSS
     1234
    567891011
    12131415161718
    19202122232425
    262728293031 
    « Apr    

    Quick Links

    • About TechBooky
    • Advertise Here
    • Contact us
    • Submit Article
    • Privacy Policy

    Recent News

    AI Helps Google One Reach 150 Million Subscribers

    AI Helps Google One Reach 150 Million Subscribers

    May 16, 2025
    FT Lists Paymenow, TymeBank & Omnisient Among Africa’s Fastest-Growing Firms

    FT Lists Paymenow, TymeBank & Omnisient Among Africa’s Fastest-Growing Firms

    May 16, 2025
    MoonPay and Mastercard Partner to Advance Stablecoin Payments

    MoonPay and Mastercard Partner to Advance Stablecoin Payments

    May 16, 2025
    Google Gemini Advanced Users Can Now Link to GitHub

    Google Gemini Advanced Users Can Now Link to GitHub

    May 16, 2025
    TikTok Accused of Violating EU Internet Content Rules

    TikTok Accused of Violating EU Internet Content Rules

    May 15, 2025
    Activists and Users Criticize NCC & Telcos Over Customer Penalties

    Activists and Users Criticize NCC & Telcos Over Customer Penalties

    May 15, 2025
    • Login

    © 2021 Design By Tech Booky Elite

    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
    • African
    • Artificial Intelligence
    • Gadgets
    • Metaverse
    • Tips
    • About TechBooky
    • Advertise Here
    • Submit Article
    • Contact us

    © 2021 Design By Tech Booky Elite

    Discover more from TechBooky

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.Ok