Screen Shot 2015-01-02 at 14.13.12


Update: We are now receiving reports that the vulnerability has been patched. People trying to use the tool are apparently now being correctly locked out from repeated password attempts.

A new tool submitted to GitHub claims to be able to perform password dictionary attacks on any iCloud account, seemingly able to evade detection from Apple’s rate-limiting security that is supposed to prevent such dictionary attacks from happening. In September, Apple reported it had closed one such hole that allowed brute-force attacks to occur.

The sourcecode for the tool has been released onto GitHub. Upon inspection, the tool is really rather crude in its complexity. It simply tries every possible word in its 500-long word-list as the password for a given iCloud account email. This means whilst it will succeed “100%” at trying 500 times over, the tool is by no means guaranteed to succeed at cracking your password.

Any password that is not simply a word from the dictionary listed on this page is safe from this ‘hack’. Still, brute-force vulnerabilities are very important as many users do use plain dictionary words as their passwords. More determined hackers could also use the exploit to brute-force much more complex passwords, so the threat is very real. For instance, hackers with more resources could use a dramatically larger word list than the one posted on GitHub.

Apple should be able to patch the hole soon, however. It is not a complicated hack — it appears to rely on pretending to be an iPhone device. For whatever reason, Apple’s servers allow these type of requests infinitely without locking password attempts after several requests.

The Photos app for has been pulled, although it’s unclear if there is any connection. Infamously, a host of celebrities had their iCloud account informatoin stolen in August 2014, causing thousands of nude and revealing photos to be posted online.

FTC: We use income earning auto affiliate links. More.

Check out 9to5Mac on YouTube for more Apple news:

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

About the Author

Benjamin Mayo

Benjamin develops iOS apps professionally and covers Apple news and rumors for 9to5Mac. Listen to Benjamin, every week, on the Happy Hour podcast. Check out his personal blog. Message Benjamin over email or Twitter.