{"id":469,"date":"2025-03-19T14:55:27","date_gmt":"2025-03-19T14:55:27","guid":{"rendered":"https:\/\/www.techrepublic.com\/?p=4298447"},"modified":"2025-03-19T14:55:27","modified_gmt":"2025-03-19T14:55:27","slug":"apple-passwords-app-vulnerability-exposed-users-for-months","status":"publish","type":"post","link":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/","title":{"rendered":"Apple Passwords App Vulnerability Exposed Users for Months"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/assets.techrepublic.com\/uploads\/2025\/03\/apple-password-app-exposed-2025.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Apple\u2019s Passwords app, designed to enhance security for iOS users, ironically left them vulnerable to phishing attacks for nearly three months. Security researchers recently revealed that the flaw exposed sensitive information, raising concerns about cybersecurity risks \u2014 even with trusted software.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"The_vulnerability_explained\"><\/span>The vulnerability explained<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Researchers at Mysk identified the flaw, which stemmed from the app\u2019s use of <a href=\"https:\/\/www.youtube.com\/watch?v=VUSB3FK1dKA\" target=\"_blank\" rel=\"noopener\">unencrypted HTTP connections<\/a> when retrieving website icons and opening password reset pages. This security lapse allowed attackers to intercept data and redirect users to malicious phishing sites.<\/p>\n<p>&gt;Mysk\u2019s team discovered that the Passwords app contacted over 130 websites using unprotected HTTP traffic. This made it possible for hackers on the same Wi-Fi network \u2014 such as in cafes, airports, or hotels \u2014 to manipulate the requests and trick users into visiting fraudulent websites designed to steal login credentials.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Apples_response_and_fix\"><\/span>Apple\u2019s response and fix<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Upon discovering the vulnerability in September 2024, Mysk promptly reported the issue to Apple. The tech giant addressed the flaw with the <a href=\"https:\/\/www.techrepublic.com\/article\/whats-new-ios182-apple\/\">iOS 18.2 update<\/a>, released in December 2024. This update implemented encrypted HTTPS connections for improved security.<\/p>\n<p>However, Apple only publicly disclosed the vulnerability in March 2025, emphasizing the importance of timely updates and robust cybersecurity measures.<\/p>\n<aside class=\"pinbox right\">\n<h3 class=\"heading\">Must-read security coverage<\/h3>\n<\/aside>\n<h2><span class=\"ez-toc-section\" id=\"What_users_should_keep_in_mind\"><\/span>What users should keep in mind<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>To protect their data, iPhone users are strongly encouraged to update their devices to the latest version of iOS. Updating to iOS 18.2 or later ensures the Passwords app operates with encrypted connections, significantly reducing <a href=\"https:\/\/www.techrepublic.com\/article\/spear-phishing-vs-phishing\/\">phishing risks<\/a>.<\/p>\n<p>Additionally, users should remain vigilant when accessing public Wi-Fi networks and consider using a reputable VPN for added protection.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Key_lessons_for_users_and_developers\"><\/span>Key lessons for users and developers<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The incident highlights the critical need for secure data transmission protocols, especially for applications managing sensitive information. While Apple quickly resolved the issue, the case serves as a reminder that even the most trusted software can have vulnerabilities.<\/p>\n<p>By keeping software up to date and&nbsp;<a href=\"https:\/\/www.techrepublic.com\/article\/how-to-protect-and-secure-data\/\">adopting best security practices<\/a>, users can better protect themselves against emerging threats in an increasingly digital world.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple\u2019s Passwords app, designed to enhance security for iOS users, ironically left them vulnerable to phishing attacks for nearly three months. Security researchers recently revealed that the flaw exposed sensitive information, raising concerns about cybersecurity risks \u2014 even with trusted software. The vulnerability explained Researchers at Mysk identified the flaw, which stemmed from the app\u2019s [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":470,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-469","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Apple Passwords App Vulnerability Exposed Users for Months - TecnoArtesanos Tech Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apple Passwords App Vulnerability Exposed Users for Months - TecnoArtesanos Tech Blog\" \/>\n<meta property=\"og:description\" content=\"Apple\u2019s Passwords app, designed to enhance security for iOS users, ironically left them vulnerable to phishing attacks for nearly three months. Security researchers recently revealed that the flaw exposed sensitive information, raising concerns about cybersecurity risks \u2014 even with trusted software. The vulnerability explained Researchers at Mysk identified the flaw, which stemmed from the app\u2019s [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/\" \/>\n<meta property=\"og:site_name\" content=\"TecnoArtesanos Tech Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-03-19T14:55:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/assets.techrepublic.com\/uploads\/2025\/03\/apple-password-app-exposed-2025.jpg\" \/>\n<meta name=\"author\" content=\"Sergio Morales\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sergio Morales\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/\",\"url\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/\",\"name\":\"Apple Passwords App Vulnerability Exposed Users for Months - TecnoArtesanos Tech Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/03\/apple-passwords-app-vulnerability-exposed-users-for-months.jpg\",\"datePublished\":\"2025-03-19T14:55:27+00:00\",\"author\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/#primaryimage\",\"url\":\"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/03\/apple-passwords-app-vulnerability-exposed-users-for-months.jpg\",\"contentUrl\":\"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/03\/apple-passwords-app-vulnerability-exposed-users-for-months.jpg\",\"width\":1400,\"height\":900},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.tecnoartesanos.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apple Passwords App Vulnerability Exposed Users for Months\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#website\",\"url\":\"https:\/\/blog.tecnoartesanos.com\/\",\"name\":\"TecnoArtesanos Tech Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.tecnoartesanos.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807\",\"name\":\"Sergio Morales\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g\",\"caption\":\"Sergio Morales\"},\"sameAs\":[\"https:\/\/sergiomorales.space\"],\"url\":\"https:\/\/blog.tecnoartesanos.com\/index.php\/author\/sergiomorales\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apple Passwords App Vulnerability Exposed Users for Months - TecnoArtesanos Tech Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/","og_locale":"en_US","og_type":"article","og_title":"Apple Passwords App Vulnerability Exposed Users for Months - TecnoArtesanos Tech Blog","og_description":"Apple\u2019s Passwords app, designed to enhance security for iOS users, ironically left them vulnerable to phishing attacks for nearly three months. Security researchers recently revealed that the flaw exposed sensitive information, raising concerns about cybersecurity risks \u2014 even with trusted software. The vulnerability explained Researchers at Mysk identified the flaw, which stemmed from the app\u2019s [&hellip;]","og_url":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/","og_site_name":"TecnoArtesanos Tech Blog","article_published_time":"2025-03-19T14:55:27+00:00","og_image":[{"url":"https:\/\/assets.techrepublic.com\/uploads\/2025\/03\/apple-password-app-exposed-2025.jpg","type":"","width":"","height":""}],"author":"Sergio Morales","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sergio Morales","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/","url":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/","name":"Apple Passwords App Vulnerability Exposed Users for Months - TecnoArtesanos Tech Blog","isPartOf":{"@id":"https:\/\/blog.tecnoartesanos.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/#primaryimage"},"image":{"@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/03\/apple-passwords-app-vulnerability-exposed-users-for-months.jpg","datePublished":"2025-03-19T14:55:27+00:00","author":{"@id":"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807"},"breadcrumb":{"@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/#primaryimage","url":"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/03\/apple-passwords-app-vulnerability-exposed-users-for-months.jpg","contentUrl":"https:\/\/blog.tecnoartesanos.com\/wp-content\/uploads\/2025\/03\/apple-passwords-app-vulnerability-exposed-users-for-months.jpg","width":1400,"height":900},{"@type":"BreadcrumbList","@id":"https:\/\/blog.tecnoartesanos.com\/index.php\/2025\/03\/19\/apple-passwords-app-vulnerability-exposed-users-for-months\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.tecnoartesanos.com\/"},{"@type":"ListItem","position":2,"name":"Apple Passwords App Vulnerability Exposed Users for Months"}]},{"@type":"WebSite","@id":"https:\/\/blog.tecnoartesanos.com\/#website","url":"https:\/\/blog.tecnoartesanos.com\/","name":"TecnoArtesanos Tech Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.tecnoartesanos.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/ec88bc1410fd158963717c4216f04807","name":"Sergio Morales","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.tecnoartesanos.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3d45178fc8fbbe32d39278bc504fa9093f947f406ff4f1ddcfa27505ab772184?s=96&d=mm&r=g","caption":"Sergio Morales"},"sameAs":["https:\/\/sergiomorales.space"],"url":"https:\/\/blog.tecnoartesanos.com\/index.php\/author\/sergiomorales\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/posts\/469","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/comments?post=469"}],"version-history":[{"count":0,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/posts\/469\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/media\/470"}],"wp:attachment":[{"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/media?parent=469"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/categories?post=469"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.tecnoartesanos.com\/index.php\/wp-json\/wp\/v2\/tags?post=469"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}