Apple has fixed a Find My iPhone exploit that allowed hackers to access personal photos stored in iCloud. This morning we learned about the massive leak of photos from about 100 celebrities.

Over the past 12 hours, the internet has been flooded with very personal photos belonging to celebrities. Anonymous users from 4chan claim to have grabbed several photos from about 100 exposed celebrity iCloud accounts. The list, as first reported by iGuRu.gr this morning, includes Jennifer Lawrence, Ariana Grande, Victoria Justice, Kate Upton, Kim Kardashian, Rihanna, Kirsten Dunst and Selena Gomez.
How;
Completely coincidentally, a day before the leak, the code for AppleID password bruteforce was uploaded to GitHub along with a proof-of-concept (PoC).
[tweet_embed id=505743531789406208]
The leaked code can exploit a vulnerability in the Find My iPhone that allowed hackers to continuously try passwords on their victims' accounts, without the page blocking them from logging in. To do this, they used brute-forcing techniques, and were able to discover the celebrities' passwords without being disturbed. Everything else is easy, as the emails needed as login names can be discovered by anyone very easily.
Apple managed to patch the exploit (strange that it reacted immediately, but you will tell me the victims were not ordinary mortals), when it was too late. Imagine what the iCloud. In addition to the photos, the hackers certainly discovered other sensitive data, such as contact lists with phone numbers and emails.
It would not be strange if several targeted phishing attacks followed names that were in the victims' contacts…
