Apple Reportedly Patches XSS Vulnerability on iCloud's Website - MacRumors
Skip to Content

Apple Reportedly Patches XSS Vulnerability on iCloud's Website

In a blog post shared by ZDNet, security researcher Vishal Bharad claims that he found a bug that would have allowed a hacker to inject a virus or malicious script onto Apple's ‌iCloud‌ website.

24330f3b719ded3a3092a6ff695d8a34

According to Bharad, the vulnerability consisted of creating a Pages or Keynote document on the ‌iCloud‌ website with the name field containing the XSS payload. Sharing the document with another user, creating a change, saving, and then clicking "Browse All Versions" under Settings would have triggered the XSS payload.

Given the vulnerability revolved around the ‌iCloud‌ website, it's not linked to a recent software update and has reportedly been patched by Apple server-side. Bharad says he submitted the issue to Apple on August 7, 2020, and received a $5,000 bounty on October 9, 2020. We've reached out to Apple for comment and we'll update if we hear back.

Popular Stories

Instagram Feature 2

PSA: Instagram Encrypted Messaging Ends on Friday, May 8

Tuesday May 5, 2026 8:24 am PDT by
Instagram will remove end-to-end encryption for direct messages between users from May 8, 2026. When the date comes around, Meta will potentially be able to see the contents of all messages between users on the social media platform. Encrypting messages has been an optional feature in Instagram since 2023, but in March of this year the social media platform quietly updated a help page to say ...
iCloud General Feature Redux

Apple Faces £3 Billion UK Trial Over iCloud Lock-In Claims

Thursday May 7, 2026 1:56 pm PDT by
Apple was not able to narrow the scope of a UK lawsuit accusing it of locking 40 million UK consumers into iCloud, to the detriment of third-party cloud storage providers. British consumer group Which? first filed the lawsuit in late 2024, and is asking for £3 billion for UK Apple customers. Apple wanted to exclude non-paying iCloud users from the lawsuit, but the tribunal denied Apple's...
iOS 26

iOS 26.5 Features: Everything New in iOS 26.5

Monday May 11, 2026 5:09 pm PDT by
Apple released iOS 26.5 after a few months of beta testing, and while it doesn't have the Siri features we were hoping for since those are being held until iOS 27, there are a handful of useful changes worth knowing about. Subscribe to the MacRumors YouTube channel for more videos. End-to-End Encryption for RCS Support for end-to-end encryption (E2EE) for RCS messages between iPhone and...

Top Rated Comments

Razorpit Avatar
68 months ago
Good thing no one ever shares a Pages or Keynote document on iCloud. Could have been catastrophic! 😉
Score: 8 Votes (Like | Disagree)
68 months ago

I joke about their usage in the real world, but I use Pages and Numbers regularly. It just feels like I'm the only one.
I use them exclusively. They work fine for local content creation and I just export to doc/excel when I need to share.
Score: 5 Votes (Like | Disagree)
68 months ago

Good thing no one ever shares a Pages or Keynote document on iCloud. Could have been catastrophic! 😉
Maybe it would of been fixed faster if Apple made pages a real competitor to Docs and Word
Score: 4 Votes (Like | Disagree)
Razorpit Avatar
68 months ago

Maybe it would of been fixed faster if Apple made pages a real competitor to Docs and Word
I joke about their usage in the real world, but I use Pages and Numbers regularly. It just feels like I'm the only one.
Score: 3 Votes (Like | Disagree)
68 months ago

Good thing no one ever shares a Pages or Keynote document on iCloud. Could have been catastrophic! 😉
Fantastically analyzed.
Score: 2 Votes (Like | Disagree)
68 months ago
I forgot Apple even had a web based interface for Pages etc. I wonder how many people use it? How much does Apple spend maintaining this?

I actually love Pages and Numbers, but I only use them via the apps.
Score: 1 Votes (Like | Disagree)