Tumblr has released an update to its iOS app, fixing a security issue that allowed the passwords of iPhone and iPad users to be compromised. The company has explained the security breach on its blog, noting that some versions of the app allowed the passwords to be detected in transit:
We have just released a very important security update for our iPhone and iPad apps addressing an issue that allowed passwords to be compromised in certain circumstances¹. Please download the update now.
If you've been using these apps, you should also update your password on Tumblr and anywhere else you may have been using the same password. It’s also good practice to use different passwords across different services by using an app like 1Password or LastPass.
Please know that we take your security very seriously and are tremendously sorry for this lapse and inconvenience.
¹ “Sniffed” in transit on certain versions of the app
Tumblr gave a statement to The Verge, noting that the company was "notified of a security vulnerability" introduced into its iOS app earlier today and therefore took immediate action to fix the issue and notify its affected users. It is unknown how many people may have been affected.