onlyTrustedInfo.comonlyTrustedInfo.comonlyTrustedInfo.com
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Reading: Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch
Share
onlyTrustedInfo.comonlyTrustedInfo.com
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Search
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
  • Advertise
  • Advertise
© 2025 OnlyTrustedInfo.com . All Rights Reserved.
Advertise here
Tech

Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch

Last updated: March 18, 2025 12:36 pm
OnlyTrustedInfo.com
Share
3 Min Read
Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch
SHARE
Advertise here

Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch

In iOS 18, Apple spun off its Keychain password management tool—previously only tucked away in Settings—into a standalone app called Passwords. It was the company’s first move at making credential management more convenient for users. It’s now been revealed that a serious HTTP bug left Passwords users vulnerable to phishing attacks for nearly three months, from the initial release of iOS 18 until the patch in iOS 18.2.

Security researchers at Mysk first discovered the flaw after noticing that their iPhone’s App Privacy Report showed Passwords had contacted a staggering 130 different websites over insecure HTTP traffic. This prompted the duo to investigate further, finding that not only was the app fetching account logos and icons over HTTP—it also defaulted to opening password reset pages using the unencrypted protocol. “This left the user vulnerable: an attacker with privileged network access could intercept the HTTP request and redirect the user to a phishing website,” Mysk told 9to5Mac.

Mysk demonstrates how a phishing attack could be carried out:

Advertise here

“We were surprised that Apple didn’t enforce HTTPS by default for such a sensitive app,” Mysk states. “Additionally, Apple should provide an option for security-conscious users to disable downloading icons completely. I don’t feel comfortable with my password manager constantly pinging each website I maintain a password for, even though the calls Passwords sends don’t contain any ID.”

Most modern websites nowadays allow unencrypted HTTP connections but automatically redirect them to HTTPS using a 301 redirect. It’s important to note that while the Passwords app before iOS 18.2 would make a request over HTTP, it would redirected to the secure HTTPS version. Under normal circumstances, this would be totally fine, as the password changes occur on an encrypted page, ensuring that credentials are not sent in plaintext.

However, it becomes a problem when the attacker is connected to the same network as the user (i.e. Starbucks, airport, or hotel Wi-Fi) and intercepts the initial HTTP request before it redirects. From here they could manipulate the traffic in a few ways. As seen in Mysk’s demo above, this includes modifying the request to redirect a phishing site that resembles Microsoft’s live.com page. The attacker can then easily gather credentials from the victims and even launch other attacks.

While this was quietly patched in December of last year, Apple only just disclosed it in the last 24 hours. The Passwords app now uses HTTPS by default for all connections, so ensure you’re running at least 18.2 on your devices! I wouldn’t be surprised if this news travels far under the radar. Share for awareness!

Follow Arin: Twitter/X, LinkedIn, Threads

Advertise here

FTC: We use income earning auto affiliate links. More.

You Might Also Like

Nintendo Says 2.2 Million People Applied to Pre-Order a Switch on the My Nintendo Store in Japan Alone — and Warns a ‘Significant’ Number of Customers Will Miss Out

Adobe releases new Firefly image generation models and a redesigned Firefly web app

Meteorologists are losing vital tool for forecasting hurricanes as the season starts

An explosion of sea urchins threatens to push coral reefs in Hawaii ‘past the point of recovery’

Yes, more and more celebrities are entering the phone business. Here’s why

Share This Article
Facebook X Copy Link Print
Share
Previous Article Pebble founder launches casual and affordable Apple Watch alternative with 30-day battery and custom faces Pebble founder launches casual and affordable Apple Watch alternative with 30-day battery and custom faces
Next Article Stability AI’s new AI model turns photos into 3D scenes Stability AI’s new AI model turns photos into 3D scenes

Latest News

Eminem’s Grandmother Betty Kresin Dies at 87: The Unresolved Trauma Behind the Rapper’s Reclusive Years
Eminem’s Grandmother Betty Kresin Dies at 87: The Unresolved Trauma Behind the Rapper’s Reclusive Years
Entertainment March 11, 2026
MGK’s ‘Stoked’ Comment on Megan Fox’s Racy Photo: The Definitive Breakdown of Their Post-Split Dynamic
MGK’s ‘Stoked’ Comment on Megan Fox’s Racy Photo: The Definitive Breakdown of Their Post-Split Dynamic
Entertainment March 11, 2026
Eric Dane’s Last Words: The AI Miracle That Let Him Speak Before He Died
Eric Dane’s Last Words: The AI Miracle That Let Him Speak Before He Died
Entertainment March 11, 2026
Saturday Night Live U.K. Sets March Premiere on Peacock with Tina Fey Hosting Debut
Saturday Night Live U.K. Sets March Premiere on Peacock with Tina Fey Hosting Debut
Entertainment March 11, 2026
//
  • About Us
  • Contact US
  • Privacy Policy
onlyTrustedInfo.comonlyTrustedInfo.com
© 2026 OnlyTrustedInfo.com . All Rights Reserved.