Apple's New Passwords App Exposed Users to Phishing Attacks for Three Months After Launch
A critical flaw in Apple’s new Passwords app exposed users to phishing attacks for three months before a patch was released.
Summary of Apple’s Passwords App Vulnerability
In iOS 18, Apple introduced the standalone Passwords app to make credential management more user-friendly. However, a significant security flaw left users vulnerable to phishing attacks for nearly three months from the initial release until it was patched in iOS 18.2.
Key Points:
- Vulnerability Discovery: Security researchers at Mysk found that the Passwords app contacted over 130 websites via unsecured HTTP, fetching account logos and icons and opening password reset pages using the same protocol.
- Security Risk: This allowed attackers with network access to intercept HTTP requests and redirect users to phishing sites, potentially stealing their credentials.
- Mitigation: Modern websites often use 301 redirects to HTTPS, which would normally secure the connection. However, an attacker on the same network could manipulate the initial HTTP request before it redirected, leading to a successful phishing attack.
- Resolution: Apple quietly patched the vulnerability in December of the previous year and disclosed it recently. The Passwords app now enforces HTTPS by default for all connections.
- User Action: Ensure your devices are running at least iOS 18.2 to benefit from the security fix.
Latest News
Nvidia
Gamers Revolt as Nvidia's Quest for Photorealism Is Branded AI Slop
30 minutes ago
Gaming
TFT Patch 16.7: Fine-Tuning the Meta for the Tactician’s Crown
2 hours ago
Gaming
Beyond the Stars: Todd Howard Unveils the Future of Elder Scrolls 6 and Bethesda's Evolution
4 hours ago
Garmin
Wrist-Based Chatting Arrives as Garmin Watches Gain Full WhatsApp Integration
4 hours ago
Nvidia
Nvidia’s DLSS 5 Faces Backlash as Generative AI Transformation Sparks Gamer Outrage
7 hours ago
Gaming
Cyberpunk TCG Shatters Kickstarter Goals with Millions Raised in Record Time
8 hours ago