Close Menu
Tech Savvyed
  • Home
  • News
  • Artificial Intelligence
  • Gadgets
  • Apps
  • Mobile
  • Gaming
  • Accessories
  • More
    • Web Stories
    • Spotlight
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

iOS 26 to Feature “Liquid Glass” UI Elements in Anticipation of 2027 iPhone Models: Report

9 June 2025

You Can Launch Steam Games From Xbox Ally’s Native Dashboard

9 June 2025

Pokémon Developer Game Freak Announces Beast Of Reincarnation For PS5, Xbox, And PC

9 June 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Tech Savvyed
SUBSCRIBE
  • Home
  • News
  • Artificial Intelligence
  • Gadgets
  • Apps
  • Mobile
  • Gaming
  • Accessories
  • More
    • Web Stories
    • Spotlight
    • Press Release
Tech Savvyed
Home » Apple’s Passwords App Had a Security Flaw That Exposed Users to Phishing Attacks for Three Months
Apps

Apple’s Passwords App Had a Security Flaw That Exposed Users to Phishing Attacks for Three Months

News RoomBy News Room19 March 20252 Mins Read
Share
Facebook Twitter Reddit Telegram Pinterest Email

Apple released a dedicated Passwords app last year, as part of the iOS 18 software update. Instead of a menu inside the Settings app, users can access their passwords and other details via a standalone app. However, the Passwords app had a serious security flaw that exposed users to potential phishing attacks from attackers who were on the same Wi-Fi network. The company recently disclosed that it fixed the security flaw three months after iOS 18 was released.

Apple Fixed Passwords App Vulnerability With iOS 18.2 Update

The iPhone maker recently amended its release notes (via 9to5Mac) for the iOS 18.2 update, which was released in December. The document now includes two entries, both titled ‘Passwords’, that describe fixes for the app. Apple has credited Mysk security researchers Talal Haj Bakry and Tommy Mysk with identifying the security vulnerability.

According to the company’s updated support document, the first patch for the Passwords app on iOS 18.2 fixed two flaws that allowed a user in a privileged network position to leak sensitive information, and alter network traffic. 

The Mysk researchers discovered that Apple’s Passwords app wasn’t using encrypted connections (HTTPS) when fetching details of specific sites, such as site icons. Similarly, password reset pages were loaded over HTTP.

The same flaw would allow an attacker on the same Wi-Fi network to intercept the network request, and direct the device to load a phishing website instead of the legitimate one. If the user trusts the webpage, they might enter their credentials on the fraudulent website.

The cybersecurity firm reported the issue to Apple in September, and Apple’s revised support document reveals that it rolled out fixes for the issue with iOS 18.2 in December. Eligible iPhone and iPad models that are running on iOS 18.2 and iPadOS 18.2 or newer versions should not be vulnerable to the flaw.

Share. Facebook Twitter Pinterest LinkedIn Telegram Reddit Email
Previous ArticleAll Marvel Rivals Galacta’s Cosmic Adventure quests & rewards
Next Article Realme P3 Ultra 5G With MediaTek Dimensity 8350 Ultra SoC Launched in India Alongside Realme P3 5G

Related Articles

Top Five ChatGPT Prompts to Boost Productivity at Work

8 June 2025

Google Chrome Gets ‘Highest Ever’ Speedometer Score; Company Reveals Optimisations Behind Improved Performance

6 June 2025

Microsoft Introduces Copilot Shopping With Native Checkout Capability in App

6 June 2025

Google’s Search Live in AI Mode Reportedly Rolling Out to Some Users

6 June 2025

Google’s Gemini Live Is Reportedly Getting a Real-Time Captions Feature

6 June 2025

Google Doubles Gemini 2.5 Pro Rate Limit for Google AI Pro Subscribers

5 June 2025
Demo
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss

You Can Launch Steam Games From Xbox Ally’s Native Dashboard

By News Room9 June 2025

Earlier today Game Informer visited an invite-only press event to play with the ROG Xbox Ally…

Pokémon Developer Game Freak Announces Beast Of Reincarnation For PS5, Xbox, And PC

9 June 2025

Phil Spencer Teases Forza, Halo Remaster, Fable, Gears Of War: E-Day For 2026

9 June 2025

Extended Clockwork Revolution Showcase Highlights Action, RPG Mechanics, Time Manipulation, And More

9 June 2025
Tech Savvyed
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact
© 2025 Tech Savvyed. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.