Apple fixes Passwords app security bug with new 18.2 update

The Apple logo is seen with the iOS 18 operating system logo in the background on a mobile device
(Image credit: Photo by Jaap Arriens/NurPhoto via Getty Images)

Apple has finally fixed a security bug with its new password manager app which could have put your data at risk.

The provider first introduced Passwords with the long-awaited iOS 18 update as a built-in application to help you manage your login details and alert you if they're compromised in a data breach. Developer and security researcher Tommy Mysk, however, found a vulnerability in its system soon after the launch.

Apple confirmed that the new 18.2 operating system update has solved the issue that an attacker could have exploited to "alter network traffic. " Mysk now urges everyone to upgrade all their Apple devices to the latest version to patch the critical issue as soon as possible.

iOS 18.2 security update

"Since iOS 18 launched, the new Passwords app has been using unencrypted HTTP to download icons for password entries – a potential security risk. We reported this bug to Apple in September, and it’s finally fixed in iOS 18.2 (CVE-2024-54492)," Mysk wrote on X on Wednesday, December 11, 2024.

HTTP (Hypertext Transfer Protocol) refers to a set of rules that allow us to communicate data on the Internet and is used to load webpages. As the iOS expert explains (see video below), malicious networks can easily intercept and manipulate insecure HTTP.

The problem was that every time you added a new password, Passwords got the account's icon from the added website (say, gmail.com, for example) and called the website over the insecure HTTP protocol.

"This malicious network overwrites the response to return a custom icon," said Mysk. "Passwords picked the custom icon and showed it in the app. This could be a malicious payload."

iOS #Security: The Passwords app has a serious security bug, UPGRADE to iOS/iPadOS 18.2 macOS 15.2 - YouTube iOS #Security: The Passwords app has a serious security bug, UPGRADE to iOS/iPadOS 18.2 macOS 15.2 - YouTube
Watch On

"This issue was addressed by using HTTPS when sending information over the network," confirmed Apple in its 18.2 security update release.

The Passwords fix is now available for all devices (iPhone and iPad 18.2, as well as macOS Sequoia 15.2) after upgrading to the latest version.

Mysk urges everyone to upgrade their devices as soon as possible, noting that also another security company, Tenable, classified the vulnerability as "critical."

The 18.2 update isn't just about fixing vulnerabilities, though. The release is probably the biggest Apple Intelligence upgrade for iPhone, iPad, and Mac so far, in fact, bringing some of the most-anticipated Apple AI features to devices including Genmoji, Image Playground, and a ChatGPT-powered Siri.

Most notably, Apple Intelligence finally extends its support for Australia, Canada, Ireland, New Zealand, South Africa, and the UK.

TOPICS
Chiara Castro
News Editor (Tech Software)

Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, cybercrime, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com

Read more
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Apple iPhone 16 Review
iOS 18.3 is here with a major change to how you enable Apple Intelligence
Latest in Cyber Security
Dark Web monitoring
How users benefit from Dark Web monitoring
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Man uses a laptop in a hotel room
4 ways to avoid misinformation on social media and retain control of your newsfeed
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring