Apple Passwords are now vulnerable to qualified phishing attacks because of a fixed vulnerability.

Users may have exposed credentials to a bad actor on a wealthy network from iOS 18, when the Passwords application debuted with the iOS 18.2 update, but you’re probably safe.
People who used Apple Passwords were vulnerable to qualified phishing attacks.
Apple used the less secure HTTP protocol, no HTTPS, when opening references or retrieving images when it released apps 18 in September 2024 with the fresh Passwords game. A malicious actor on a secure network could then catch the HTTP request, redirect users to a fraudulent website, and obtain the login information.
The Passwords game was patched in December with apps 18.2 in response to the safety study firm Mysk, which discovered this problem and reported it to Apple in September. That implies that for those three months, the risk was present in the wild and would continue to exist for people releasing iOS before iOS 18.2.
Last checking on AppleInsider | Discuss in our communities