Privacy

Apple iOS 18.0.1 Patches Password Exposure and Audio Snippet Bugs

According to a barebones Apple advisory, the new iOS 18.0.1 fixes two bugs that expose passwords and audio snippets to malicious hackers.

iPhone security

Apple has pushed out a security-themed iOS and iPadOS update to fix a pair of flaws in the mobile operating systems.

According to a barebones Apple advisory, the new iOS 18.0.1 and iPadOS 18.0.1 fixes vulnerabilities that expose passwords and audio snippets to malicious hackers.

One issue, tracked as CVE-2024-44207, allowed audio messages in Messages to capture brief snippets of audio before the microphone indicator was activated. 

The second bug, CVE-2024-44204, could potentially enable VoiceOver to read aloud a user’s saved passwords due to a logic issue.

Apple said the mobile OS point-updates include improved validation and checks.

There are no indications that any of the two bugs were exploited prior to the availability of patches.

Advertisement. Scroll to continue reading.

The update also fixes issues where Touch screen may be temporarily unresponsive, camera freezes, the Messages app unexpectedly crashing, and undocumented performance issues.

Apple shipped iOS 18 less than a month ago with fixes for at least 33 security vulnerabilities that expose iPhones and iPads to an assortment of malicious hacker attacks.

Related: Apple Patches Major Security Flaws With iOS 18 Refresh

Related: Apple Suddenly Drops NSO Group Spyware Lawsuit

Related: Apple Warns of Newly Exploited iOS 17 Kernel Zero-Day

Related: Apple Blunts Zero-Day Attacks With iOS 17.4 Update

Related Content

Mobile & Wireless

Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team.

Vulnerabilities

The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks.

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover.

Mobile & Wireless

The bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data.

Endpoint Security

Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass.

Endpoint Security

Apple announced that dozens of vulnerabilities have been patched in each of its operating systems.

Vulnerabilities

The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users.

Application Security

The company blocked over 1.1 billion accounts and $2.2 billion in potentially fraudulent transactions.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version