It appeared on Tuesday that a serious http bug in Apple's password application left vulnerable users to phishing attacks for an amazing three months after its beginnings last year.
A solution for vulnerability was included in updating the iOS 18.2 software, which was deployed on December 11 of last year. But the sources indicate that the bug was there, not corrected, since the launch of iOS 18.0 (and the application of passwords itself) on September 16.
My MySK's “occasional security researchers” spotted the problem when they noticed that passwords were going to look for logos and icons via un encrypted http traffic and also lacks HTTP when opening the passwords reset pages.
“It left the user vulnerable,” said the company at 9TO5MAC, which explains the problem in more detail than I will try here. “An attacker with access to the privileged network could intercept the HTTP demand and redirect the user to a phishing website. [and] Apple should provide an option for users concerned for safety to completely deactivate icons download. »»
Mysk's words were treated and Apple corrected the buckt by making passwords to use HTTPS by default. This change was made quietly in iOS 18.2 in December, but was only announced on March 17: “This problem was resolved using HTTPS when sending information on the network,” said Apple now in its IOS 18.2 safety content page, crediting Talal Haj Bakry and Tommy Mysk de Mysk Inc. for discovery.
Low profile safety fixes are one of the reasons why we recommend software updates in a timely time on your Apple devices. To update iOS on your iPhone, open the Settings application, access to General > Software updateAnd follow the instructions on the screen.



