Apple Reportedly Patches XSS Vulnerability on iCloud's Website - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Apple Reportedly Patches XSS Vulnerability on iCloud's Website

In a blog post shared by ZDNet, security researcher Vishal Bharad claims that he found a bug that would have allowed a hacker to inject a virus or malicious script onto Apple's ‌iCloud‌ website.

24330f3b719ded3a3092a6ff695d8a34

According to Bharad, the vulnerability consisted of creating a Pages or Keynote document on the ‌iCloud‌ website with the name field containing the XSS payload. Sharing the document with another user, creating a change, saving, and then clicking "Browse All Versions" under Settings would have triggered the XSS payload.

Given the vulnerability revolved around the ‌iCloud‌ website, it's not linked to a recent software update and has reportedly been patched by Apple server-side. Bharad says he submitted the issue to Apple on August 7, 2020, and received a $5,000 bounty on October 9, 2020. We've reached out to Apple for comment and we'll update if we hear back.

Popular Stories

iCloud General Feature Redux

iCloud+ Subscribers Get Higher Apple Intelligence Usage Limits in iOS 27

Tuesday June 9, 2026 6:05 am PDT by
Certain Apple Intelligence features in iOS 27 will carry daily usage limits, with iCloud+ subscribers receiving higher allowances than free users. The company reiterated the details in its press release accompanying yesterday's Apple Intelligence announcements. Apple said the limits apply to features that rely on "powerful server models," with image generation cited as the primary example....
iCloud iPhone 17 Pro

iPhone Users Who Pay for iCloud Storage Get Two New Perks on iOS 27

Thursday July 2, 2026 6:10 am PDT by
If you pay for certain iCloud+ storage plans beyond the 5GB that Apple offers for free, you will receive two more perks on iOS 27 at no additional cost. A summary of the two new iCloud+ perks on iOS 27:Increased daily usage limits for some new Apple Intelligence features, including image generation in the revamped Image Playground app. HomeKit Secure Video cameras receive generated video...
iCloud General Feature Redux

Apple's New Hide My Email Domain Makes It Easier to Block iCloud Aliases

Wednesday June 17, 2026 7:41 am PDT by
Apple's decision to move Hide My Email to a dedicated "private.icloud.com" domain appears to have the consequence of making it easier for platforms that want to block iCloud aliases to do so. Apple is unifying the email domains used by Sign in with Apple and iCloud+ Hide My Email under a single private.icloud.com domain later this summer. Sign in with Apple currently uses...

Top Rated Comments

Razorpit Avatar
70 months ago
Good thing no one ever shares a Pages or Keynote document on iCloud. Could have been catastrophic! 😉
Score: 8 Votes (Like | Disagree)
70 months ago

I joke about their usage in the real world, but I use Pages and Numbers regularly. It just feels like I'm the only one.
I use them exclusively. They work fine for local content creation and I just export to doc/excel when I need to share.
Score: 5 Votes (Like | Disagree)
70 months ago

Good thing no one ever shares a Pages or Keynote document on iCloud. Could have been catastrophic! 😉
Maybe it would of been fixed faster if Apple made pages a real competitor to Docs and Word
Score: 4 Votes (Like | Disagree)
Razorpit Avatar
70 months ago

Maybe it would of been fixed faster if Apple made pages a real competitor to Docs and Word
I joke about their usage in the real world, but I use Pages and Numbers regularly. It just feels like I'm the only one.
Score: 3 Votes (Like | Disagree)
70 months ago

Good thing no one ever shares a Pages or Keynote document on iCloud. Could have been catastrophic! 😉
Fantastically analyzed.
Score: 2 Votes (Like | Disagree)
70 months ago
I forgot Apple even had a web based interface for Pages etc. I wonder how many people use it? How much does Apple spend maintaining this?

I actually love Pages and Numbers, but I only use them via the apps.
Score: 1 Votes (Like | Disagree)