Apple has announced that a new security update is available that fixes a critical vulnerability in the Apple Password app. If you haven’t updated your phone to the latest version of iOS, check and upgrade your system now. This update will help iPhone owners reduce the risk of falling victim to previously unknown security vulnerabilities.
The vulnerability allows malicious actors to access stored usernames and passwords. The Apple Password app makes it easy for users to quickly log in to a website using saved credentials, but it should only work on a secure network; in other words, the URL should start with “HTTPS.” Security researchers first discovered the issue when more than 130 insecure websites (those that only use HTTP) were connecting to the Password app.

Without proper verification, an attack could redirect users to nearly identical websites designed to steal their login credentials. Fortunately, the latest patch fixes this issue by ensuring the Passwords app only uses HTTPS connections by default. However, your iPhone needs to be running at least iOS 18.2 or later.
In general, you should try to use the latest version of iOS whenever possible. Version 18.3.2 also fixed a security hole that left iPhone users vulnerable to attack. While most operating system updates add new features, many also fix unwanted bugs that can pose a risk to end users.
While updating your operating system may not always be convenient—especially if your phone's storage is almost full and you have to free up space to download the update—it's a good thing to do, and it makes your device more secure.