iOS 16 'Mailjack' Bug Causes Mail App to Crash Upon Receiving Maliciously Crafted Email: All Details

The bug comes in the form of an otherwise routine-looking mail message with an unusual "from" field containing extra characters that trigger the crash.

Advertisement
Written by Anees Hussain, Edited by David Delima | Updated: 23 September 2022 19:30 IST
Highlights
  • The iOS 16 "Mailjack" email bug was discovered by Equinux
  • The bug could lock users running on iOS 16 out of their email app
  • Users may delete these emails through a device running an older iOS
iOS 16 'Mailjack' Bug Causes Mail App to Crash Upon Receiving Maliciously Crafted Email: All Details

The bug dubbed "Mailjack" allows outsiders to hijack the iOS 16 Mail app

An iOS 16 bug is reportedly causing the Mail application on iPhone and iPad models that have been updated to the latest version of Apple's operating system to crash, rendering it inaccessible. The bug comes in the form of an otherwise routine-looking mail message, that has an unusual sender field that includes extra characters that causes the Mail application to crash on iOS 16. The bug has been dubbed “Mailjack” and allows any outsider to lock iPhone and iPad users out of their email accounts with a modified email.

The crash-triggering email was identified by Equinux's VPN Tracker. Generally, the “From” field has the sender's name followed by their email address in the syntax — From: sender@example.com. However, the crash-triggering email had the from field syntax as — From: ""@example.com. Mail services like Gmail, Outlook, and Hotmail automatically rewrite such inbound emails with unusual syntax to prevent such triggers.

While Gmail and Yahoo have filters in place to block these maliciously crafted emails altogether, Apple's first-party iCloud Mail does not appear to have any such rewriting or filtering mechanisms in place, as per the report.

The current solution to avoiding the trigger is to delete the message from the inbox or spam folder from a device that is running an older iOS version or via an external email client. Users may also choose to move the trigger email to another subfolder on an IMAP email account. However, navigating to the respective subfolder will cause the application to crash again according to the website. Admins may also choose to add the syntax ""@example.com to their list of blocked emails via email security software or firewall.

Advertisement

Equinux's VPN Tracker has created a dedicated webpage where users can test the bug trigger by entering their email address. However, users are advised not to try this as it could lock them out of their emails unless they have access to an older iOS or external email client to delete the triggering message.


Apple unveiled eight new products at its September ‘Far Out' event. Which ones will float — and which will sink? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: iOS 16, Apple, mail, Mailjack, bugs
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo Y400 Pro 5G With 5,500mAh Battery Launched in India: Price, Features
  2. Oppo Reno 14 5G Series Teased to Launch in India Soon
  3. Nothing Headphone 1 Renders Leaked Ahead of July 1 Launch: See Design
  4. Nothing Phone 3 to Get New Glyph Matrix Interface on the Rear Panel
  5. Samsung Galaxy S25 FE Leaked Render Suggests Improved Design
  6. 16 Billion Login Credentials Have Been Leaked in Massive Data Breach
  7. Oppo Find X9 Pro Leak Suggests Potential Camera Specifications
  8. Samsung Galaxy M36 5G India Launch Date and Key Features Revealed
  9. OTT Releases This Week: Ground Zero, Detective Sherdil, Found S2, and More
  1. Vivo X Fold 5 India Launch Reportedly Set for Mid-July
  2. Trump Extends Deadline for US TikTok Sale to September
  3. Nothing Headphone 1 Renders and Live Images Leak Ahead of July 1 Launch; Shows Unique Design
  4. BBC Said to Have Threatened Legal Action Against AI Start-up Perplexity Over Content Scraping
  5. Adobe Launches Project Indigo, a Camera App for iPhone With Full Manual Controls
  6. Oppo Find X9 Pro Camera Details Leaked; Said to Feature Samsung ISOCELL HP5 Sensor
  7. Nintendo Switch 2 Third-Party Game Sales Reportedly 'Very Low' Despite Console's Record Launch
  8. 16 Billion Login Credentials Leaked in Massive Data Breach Impacting Apple, Google and More
  9. Vivo Y400 Pro 5G With 50-Megapixel Rear Camera, 5,500mAh Battery Launched in India: Price, Specifications
  10. Samsung Galaxy S25 FE Renders Leak Online, Suggesting Familiar Design With Thinner Bezels
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.