Passwords App is accessing websites from ASCredentialIdentityStore associated with 3rd Party password management app

The Passwords App is accessing websites found in the ASCredentialIdentityStore associated with a 3rd Party password management app (SamuraiSafe). This behaviour appears to be associated with looking up website favicons in order to display in Passwords. However the websites contacted are not stored in the Passwords App/iCloud KeyChain - only the 3rd Party password management app (SamuraiSafe). This is effectively leaking website information stored in the 3rd Party password management app.

I first noticed this behaviour on macOS, and it appears to happen every 8 days. Today it was seen on iOS.

The behaviour is revealed through the App Privacy Report on iOS (and LittleSnitch on macOS).

I would not be surprised to see the Passwords App do this for websites saved in the Passwords App/iCloud KeyChain, however I believe it should not be arbitrarily testing every website found in the ASCredentialIdentityStore as reference to that website url should be entirely under the control of the end user.

See attached screenshots from App Privacy Report.

Filed bug with Apple: FB16682423

Passwords App is accessing websites from ASCredentialIdentityStore associated with 3rd Party password management app
 
 
Q