Developer Demonstrates iOS Phishing Attack That Uses Apple-Style Password Request

Developer Felix Krause today shared a proof of concept phishing attack that's gaining some traction as it clearly demonstrates how app developers can use Apple-style popups to gain access to an iPhone user's Apple ID and password.

As Krause explains, iPhone and iPad users are accustomed to official Apple requests for their Apple ID and password for making purchases and accessing iCloud, even when not in the App Store or iTunes app.

phishingconcept1
Using a UIAlertController that emulates the design of the system request for a password, developers can create an identical interface as a phishing tool that can fool many iOS users.

Showing a dialog that looks just like a system popup is super easy, there is no magic or secret code involved, it's literally the examples provided in the Apple docs, with a custom text.

I decided not to open source the actual popup code, however, note that it's less than 30 lines of code and every iOS engineer will be able to quickly build their own phishing code.

Though some of the system alerts would require a developer to have a user's Apple ID email address, there are also popup alerts that do not require an email and can recover a password.

phishingconcept2
The phishing method that Krause describes is not new, and Apple vets apps that are accepted to the App Store, but it's worth highlighting for iOS users who may not be aware that such a phishing attempt is possible.

As Krause says, users can protect themselves by being wary of these popup dialogues. If one pops up, press the Home button to close the app. If the popup goes away, it's tied to the app and is a phishing attack. If it remains, it's a system request from Apple.

Krause also recommends users dismiss popups and enter their credentials directly within the Settings app.

Krause has reported the issue to Apple and recommends a fix that would include Apple asking customers to enter their credentials into the Settings app rather than directly through a popup that can be easily mimicked. Alternatively, he suggests credential requests could include an app icon to indicate that an app is asking rather than the system.

As extra protection from attacks like this, Apple customers should enable two-factor authentication as it prevents attackers from being able to log into an Apple ID account without a code from a verified device.

Top Rated Comments

b11051973 Avatar
81 months ago
Always enter an incorrect password first. If it doesn't complain you entered the wrong password, you know it is a phishing thingie.
Score: 47 Votes (Like | Disagree)
nutmac Avatar
81 months ago
Similarly, macOS's Authorization Service dialog box is also easily spoofed.

Similar to Windows' Control-Alt-Delete, Apple's iOS and macOS should make it impossible to spoof these dialog boxes.
Score: 28 Votes (Like | Disagree)
alex00100 Avatar
81 months ago
This is very smart actually... I'm surprised this isn't massively used by shady apps already.
Score: 15 Votes (Like | Disagree)
BMcCoy Avatar
81 months ago
Yup, I’d fall for this.
And I’m paranoid.

Cunning.
And a bit frightening.
Score: 11 Votes (Like | Disagree)
thespacekid Avatar
81 months ago
I just transferred to a new iPhone and it asked many times for my apple id password at seemingly random times. Sometimes I'm never sure if I mistyped the password or it was a new request for something else. Apple needs to get more organized and at least let the user know why they have to enter the password.
Score: 10 Votes (Like | Disagree)
ignatius345 Avatar
81 months ago
Fair point about our social conditioning on these dialogs. I don't know of a good way to address this though.
I think this one is on Apple. A user gets legitimately asked for his/her password enough times and fatigue sets in, and they stop really thinking about it.

Ultimately it's a UX problem that needs to be solved so that entering one's iCloud password is 1) hard to fake and 2) doesn't happen any more often than necessary.
Score: 10 Votes (Like | Disagree)

Popular Stories

iPhone 15 General Feature Black

New iOS Features Coming in 2024 for Messages, Apple Music, and More

Thursday December 28, 2023 7:30 am PST by
2024 is just a few days away, and there are many iOS 17 and iOS 18 features that are expected to launch throughout the year. Below, we have recapped new iOS features expected in 2024, including Stolen Device Protection, collaborative Apple Music playlists, AirPlay on hotel room TVs, app sideloading in the EU, next-generation CarPlay, roadside assistance via satellite outside of the U.S., RCS ...
iOS 17

iOS 17.3 Will Add These Two Useful Features to Your iPhone

Sunday December 24, 2023 8:59 am PST by
Apple released the first beta of iOS 17.3 earlier this month, and the upcoming software update includes two new features so far. iOS 17.3 will likely be released in January like iOS 16.3 and iOS 15.3 were, but February is also a possibility if testing is prolonged. Below, we provide additional details about the new features in iOS 17.3 so far. Stolen Device Protection Earlier this...
iPhone 17 Five Features Header

iPhone 17: Five Features Apple Plans to Save for 2025

Thursday December 28, 2023 2:00 am PST by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models concurrently, which is why we sometimes get rumored feature leaks so far ahead of launch. The iPhone 17 series is no different, and already we have some idea of what to expect from Apple's 2025 smartphone lineup. If you plan to skip...
Mac Gaming

Apple Discusses Push Towards High-End Mac Gaming in New Interview

Thursday December 28, 2023 6:19 am PST by
Inverse's Raymond Wong today published an in-depth overview of Apple's increasing push towards high-end gaming on the Mac. The story includes commentary from Apple marketing managers Gordon Keppel and Leland Martin. One of the biggest reasons that gaming has improved on the Mac in recent years is the switch from Intel processors to Apple silicon, resulting in MacBooks providing...
Apple Watch Series 9

Apple Watch Series 9 and Ultra 2 Available in Apple Stores Starting Today, Online Sales to Resume Tomorrow

Wednesday December 27, 2023 2:28 pm PST by
Apple Watch Series 9 and the Apple Watch Ultra 2 are back in some of Apple's retail stores in the United States today, according to Bloomberg's Mark Gurman. Select stores will have availability today, while all stores will have the Apple Watch models back in stock by December 30. Online sales of the devices are set to resume tomorrow by 12:00 p.m. Pacific Time. Apple is able to begin selling ...
iPhone 15 Blue Three Quarters Perspective Camera Closeup Feature

6 Essential iPhone Camera Tips for Taking Great Photos

Tuesday December 26, 2023 3:00 am PST by
Apple's iPhones include several headline camera features that are worth using, such as Portrait Mode and Photographic Styles. But if all you want to use is the standard photo mode, there are still several tools and settings that can improve the composition of your pictures and help you capture the perfect shot using more traditional techniques. Whether you are the owner of a new iPhone or a...
Apple Watch Series 9

Apple Watch Series 9 and Ultra 2 Sales Ban Paused by US Appeals Court

Wednesday December 27, 2023 8:49 am PST by
The ban on imports of Apple Watch Series 9 and Apple Watch Ultra 2 models has today been temporarily paused, meaning that the devices can now go back on sale for a short while longer in the United States. Apple filed an emergency request to the United States Court of Appeals following President Biden's decision to decline a veto on the sales ban, allowing it to take effect earlier this week. ...