Apple’s OS has a tendency to randomly display iCloud login prompts anyway, and the exploit can be programmed to ask for a password only once, so as not to arouse suspicion. So, it’s not terribly difficult to imagine a slew of unsuspecting Apple users getting caught in this sort of phishing scheme.

Advertisement
Advertisement

The security researcher says he first reported the flaw to Apple back in January. Six months and no sign of a fix later, he decided to publish his exploit online. The strategy seems to be paying off: several days ago, Apple officials told Ars Technica that the company is now working on a fix for an upcoming software update.

In the meanwhile, if you’re an Apple user who hasn’t activated two-step verification, this would be a great time to do so.

Advertisement

[Ars Technica]