onlyTrustedInfo.comonlyTrustedInfo.comonlyTrustedInfo.com
Notification
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Reading: Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch
Share
onlyTrustedInfo.comonlyTrustedInfo.com
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Search
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
  • Advertise
  • Advertise
© 2025 OnlyTrustedInfo.com . All Rights Reserved.
Tech

Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch

Last updated: March 18, 2025 12:36 pm
Oliver James
Share
3 Min Read
Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch
SHARE
Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch

In iOS 18, Apple spun off its Keychain password management tool—previously only tucked away in Settings—into a standalone app called Passwords. It was the company’s first move at making credential management more convenient for users. It’s now been revealed that a serious HTTP bug left Passwords users vulnerable to phishing attacks for nearly three months, from the initial release of iOS 18 until the patch in iOS 18.2.

Security researchers at Mysk first discovered the flaw after noticing that their iPhone’s App Privacy Report showed Passwords had contacted a staggering 130 different websites over insecure HTTP traffic. This prompted the duo to investigate further, finding that not only was the app fetching account logos and icons over HTTP—it also defaulted to opening password reset pages using the unencrypted protocol. “This left the user vulnerable: an attacker with privileged network access could intercept the HTTP request and redirect the user to a phishing website,” Mysk told 9to5Mac.

Mysk demonstrates how a phishing attack could be carried out:

“We were surprised that Apple didn’t enforce HTTPS by default for such a sensitive app,” Mysk states. “Additionally, Apple should provide an option for security-conscious users to disable downloading icons completely. I don’t feel comfortable with my password manager constantly pinging each website I maintain a password for, even though the calls Passwords sends don’t contain any ID.”

Most modern websites nowadays allow unencrypted HTTP connections but automatically redirect them to HTTPS using a 301 redirect. It’s important to note that while the Passwords app before iOS 18.2 would make a request over HTTP, it would redirected to the secure HTTPS version. Under normal circumstances, this would be totally fine, as the password changes occur on an encrypted page, ensuring that credentials are not sent in plaintext.

However, it becomes a problem when the attacker is connected to the same network as the user (i.e. Starbucks, airport, or hotel Wi-Fi) and intercepts the initial HTTP request before it redirects. From here they could manipulate the traffic in a few ways. As seen in Mysk’s demo above, this includes modifying the request to redirect a phishing site that resembles Microsoft’s live.com page. The attacker can then easily gather credentials from the victims and even launch other attacks.

While this was quietly patched in December of last year, Apple only just disclosed it in the last 24 hours. The Passwords app now uses HTTPS by default for all connections, so ensure you’re running at least 18.2 on your devices! I wouldn’t be surprised if this news travels far under the radar. Share for awareness!

Follow Arin: Twitter/X, LinkedIn, Threads

FTC: We use income earning auto affiliate links. More.

You Might Also Like

At least 4 dead after heavy rains flood San Antonio

10 Incredible Sea Turtle Facts to Celebrate World Sea Turtle Day

Best bookmarking apps to help organize and declutter your digital life 

A Camouflaged Black Bear Blends in with the Rocks and Snatches a Juicy Fish for Lunch

Your VPN could be giving your browsing data to China, watchdog says

Share This Article
Facebook X Copy Link Print
Share
Previous Article Pebble founder launches casual and affordable Apple Watch alternative with 30-day battery and custom faces Pebble founder launches casual and affordable Apple Watch alternative with 30-day battery and custom faces
Next Article Stability AI’s new AI model turns photos into 3D scenes Stability AI’s new AI model turns photos into 3D scenes

Latest News

Steelers announce Ben Roethlisberger, Joey Porter, Maurkice Pouncey to join Hall of Honor
Steelers announce Ben Roethlisberger, Joey Porter, Maurkice Pouncey to join Hall of Honor
Sports July 28, 2025
Phillies’ Nick Castellanos out of Saturday’s lineup vs. Yankees with left knee injury
Phillies’ Nick Castellanos out of Saturday’s lineup vs. Yankees with left knee injury
Sports July 28, 2025
2025 Tour de France standings going into final stage, with Tadej Pogačar set to win 2nd consecutive trophy
2025 Tour de France standings going into final stage, with Tadej Pogačar set to win 2nd consecutive trophy
Sports July 28, 2025
2025 MLB betting: Nick Kurtz now a massive favorite to win AL Rookie of the Year
2025 MLB betting: Nick Kurtz now a massive favorite to win AL Rookie of the Year
Sports July 28, 2025
//
  • About Us
  • Contact US
  • Privacy Policy
onlyTrustedInfo.comonlyTrustedInfo.com
© 2025 OnlyTrustedInfo.com . All Rights Reserved.