Close Menu
West TimelinesWest Timelines
  • News
  • Politics
  • World
    • Africa
    • Asia
    • Australia
    • Europe
      • United Kingdom
      • Germany
      • France
      • Italy
      • Russia
      • Spain
      • Turkey
      • Ukraine
    • North America
      • United States
      • Canada
    • South America
  • Business
    • Finance
    • Markets
    • Investing
    • Small Business
    • Crypto
  • Elections
  • Entertainment
  • Health
  • Lifestyle
    • Fashion
    • Food & Drink
    • Travel
    • Astrology
  • Weird News
  • Science
  • Sports
    • Soccer
  • Technology
  • Viral Trends
Trending Now

Dubai Spotlight: Analyzing the Evolving Audience Tastes with AI Social Listening Tools in the UAE

2 weeks ago

مرآة التاريخ: تحليل البناء السردي للدروس الخالدة في قصص الأنبياء والإسلام

3 weeks ago

السندات الحكومية والشركات: أساسيات الاستثمار الآمن والدخل الثابت

4 weeks ago

UAE Ranks Among Top Rugby Markets on TOD as British & Irish Lions Tour Kicks Off

5 months ago

Darven: A New Leap in AI-Powered Legal Technology Launching from the UAE to the World

5 months ago
Facebook X (Twitter) Instagram
West TimelinesWest Timelines
  • News
  • US
  • #Elections
  • World
    • North America
      • United States
      • Canada
    • Europe
      • United Kingdom
      • Germany
      • France
      • Italy
      • Spain
      • Ukraine
      • Russia
      • Turkey
    • Asia
    • Australia
    • Africa
    • South America
  • Politics
  • Business
    • Finance
    • Investing
    • Markets
    • Small Business
    • Crypto
  • Lifestyle
    • Astrology
    • Fashion
    • Food & Drink
    • Travel
  • Health
  • Sports
    • Soccer
  • More
    • Entertainment
    • Technology
    • Science
    • Viral Trends
    • Weird News
Subscribe
  • Israel War
  • Ukraine War
  • United Kingdom
  • Canada
  • Germany
  • France
  • Italy
  • Russia
  • Spain
  • Turkey
  • Ukraine
West TimelinesWest Timelines
Home»Technology
Technology

rewrite this title Apple’s Passwords App Security Flaw Was Potentially There ‘For Years’

9 months agoNo Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Telegram Email WhatsApp Copy Link

Summarize this content to 2000 words in 6 paragraphs A bug in the iOS Passwords app that meant iPhone users were susceptible to potential phishing attacks has been fixed after possibly being present for years.In a note on its security page, Apple described the issue as one where “a user in a privileged network position may be able to leak sensitive information.” The problem was fixed by using HTTPS when sending information over the network, the tech giant said.The bug, first discovered by security researchers at Mysk, was reported back in September but appeared to be left unfixed for several months. In a tweet Wednesday, Mysk said Apple Passwords used an insecure HTTP by default since the compromised password detection feature was introduced in iOS 14, which was released back in 2020.”iPhone users were vulnerable to phishing attacks for years, not months,” Mysk tweeted. “The dedicated Passwords app in iOS 18 was essentially a repackaging of the old password manager that was in the Settings, and it carried along all of its bugs.”That said, the likelihood of someone falling victim to this bug is very low. The bug was also addressed in security updates for other products, including the Mac, iPad and Vision Pro.In the caption of a YouTube video posted by Mysk highlighting the issue, the researchers showed how the iOS 18 Passwords app had been opening links and downloading account icons over insecure HTTP by default, making it vulnerable to phishing attacks. The video highlights how an attacker with network access could intercept and redirect requests to a malicious site.According to 9to5Mac, the issue poses a problem when the attacker is on the same network as the user, such as at a coffee shop or airport, and intercepts the HTTP request before it redirects.Apple didn’t respond to a request for comment about the issue or provide further details.Mysk said spotting the bug did not qualify for a monetary bounty because it didn’t meet the impact criteria or fall into any of the eligible categories.”Yes, it feels like doing charity work for a $3 trillion company,” the company tweeted. “We didn’t do this primarily for money, but this shows how Apple appreciates independent researchers. We had spent a lot of time since September 2024 trying to convince Apple this was a bug. We’re glad it worked. And we’d do it again.”A potential security slipupGeorgia Cooke, a security analyst at ABI Research, called the issue “not a small-fry bug.””It’s a hell of a slip from Apple, really,” Cooke said. “For the user, this is a concerning vulnerability demonstrating failure in basic security protocols, exposing them to a long-standing attack form which requires limited sophistication.” According to Cooke, most people probably won’t run into this issue because it requires a pretty specific set of circumstances, such as choosing to update your login from a password manager, doing it on a public network and not noticing if you’re being redirected. That said, it’s a good reminder of why keeping your devices updated regularly is so important.She added that people can take extra steps to protect themselves from these kinds of vulnerabilities, especially on shared networks. This includes routing device traffic through a virtual private network, avoiding sensitive transactions such as credential changes on public Wi-Fi and not reusing passwords.
!function(f,b,e,v,n,t,s)
{if(f.fbq)return;n=f.fbq=function(){n.callMethod?
n.callMethod.apply(n,arguments):n.queue.push(arguments)};
if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version=’2.0′;
n.queue=[];t=b.createElement(e);t.async=!0;
t.src=v;s=b.getElementsByTagName(e)[0];
s.parentNode.insertBefore(t,s)}(window, document,’script’,
‘https://connect.facebook.net/en_US/fbevents.js’);
fbq(‘set’, ‘autoConfig’, false, ‘789754228632403’);
fbq(‘init’, ‘789754228632403’);

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest Email Telegram WhatsApp Copy Link

You Might Like

Dubai Spotlight: Analyzing the Evolving Audience Tastes with AI Social Listening Tools in the UAE

Darven: A New Leap in AI-Powered Legal Technology Launching from the UAE to the World

Array

Array

Array

Array

Editors Picks

مرآة التاريخ: تحليل البناء السردي للدروس الخالدة في قصص الأنبياء والإسلام

3 weeks ago

السندات الحكومية والشركات: أساسيات الاستثمار الآمن والدخل الثابت

4 weeks ago

UAE Ranks Among Top Rugby Markets on TOD as British & Irish Lions Tour Kicks Off

5 months ago

Darven: A New Leap in AI-Powered Legal Technology Launching from the UAE to the World

5 months ago

Jordan to Host Iraq in the Final Round of the Asian World Cup Qualifiers After Securing Historic Spot

6 months ago

Latest News

فلسطين: قلبٌ ينبض بالصمود والأمل

6 months ago

Roland Garros 2025: A New Era of Viewing, A Tribute to Legends, and Moments to Remember

7 months ago

Array

7 months ago
Advertisement
Facebook X (Twitter) TikTok Instagram Threads
© 2025 West Timelines. All Rights Reserved. Developed By: Sawah Solutions
  • Privacy Policy
  • Terms
  • Contact

Type above and press Enter to search. Press Esc to cancel.