A serious HTTP bug in Apple Passwords left users vulnerable to phishing attacks for nearly three months.Security researchers at Mysk discovered the flaw, which allowed attackers to intercept HTTP requests.The bug was quietly patched in December, but Apple only recently disclosed the vulnerability.Mysk, the researchers who found the bug, did not receive a bounty from Apple for their discovery.