A security flaw in iCloud apparently allowed would-be hackers to repeatedly try different passwords on user accounts of the service, without them locking out as usual after a number of failed attempts. So, in theory, it was possible to access any account after a lot of effort and a good dose of luck.
As protothema reports, Apple immediately addressed and fixed the security flaw.
On New Year's Day, someone using the alias pr0x13 released an iCloud account hacking "tool." The program was called iDict and essentially automatically tried thousands of passwords against a long list of commonly used words and phrases. Its creator claimed that it could even bypass Apple's security questions or two-factor authentication.
The next day, user @pr0x13 wrote on Twitter that the security flaw had been fixed and iDict no longer works.
iCloud was the target of attacks a few months ago, with many actresses, models and singers claiming that their accounts had been hacked, resulting in the leak of usually "spicy" photos.
Apple had then claimed that the leak incidents were the result of targeted attacks and not a security flaw, without anyone knowing how many accounts were actually compromised and how many celebrities took advantage of the noise created to return to the news, even temporarily.

