iOS Mail App Flaw May Have Allowed Hackers to Steal Data for Years, Apple to Roll Out Fix

The iOS Mail app flaw bug was discovered by ZecOps, a San Francisco-based mobile security forensics company.

Advertisement
By Reuters | Updated: 23 April 2020 10:32 IST
Highlights
  • Apple acknowledged vulnerability, said fix coming in next update
  • ZecOps says the flaw exploitable since January 2018
  • Apple largely viewed as having a high standard for digital security

Apple is viewed within the cybersecurity industry as having a high standard for digital security

Apple is planning to fix a flaw that a security firm said may have left more than half a billion iPhones vulnerable to hackers.

The bug, which also exists on iPads, was discovered by ZecOps, a San Francisco-based mobile security forensics company, while it was investigating a sophisticated cyberattack against a client that took place in late 2019. Zuk Avraham, ZecOps' chief executive, said he found evidence the vulnerability was exploited in at least six cybersecurity break-ins.

Advertisement

An Apple spokesman acknowledged that a vulnerability exists in Apple's software for email on iPhones and iPads, known as the Mail app, and that the company had developed a fix, which will be rolled out in a forthcoming update on millions of devices it has sold globally.

Apple declined to comment on Avraham's research, which was published on Wednesday, that suggests the flaw could be triggered from afar and that it had already been exploited by hackers against high-profile users.

Advertisement

Avraham said he found evidence that a malicious program was taking advantage of the vulnerability in Apple's iOS mobile operating system as far back as January 2018. He could not determine who the hackers were and Reuters was unable to independently verify his claim.

To execute the hack, Avraham said victims would be sent an apparently blank email message through the Mail app forcing a crash and reset. The crash opened the door for hackers to steal other data on the device, such as photos and contact details.

Advertisement

ZecOps claims the vulnerability allowed hackers to remotely steal data off iPhones even if they were running recent versions of iOS. By itself, the flaw could have given access to whatever the Mail app had access to, including confidential messages.

Avraham, a former Israeli Defense Force security researcher, said he suspected that the hacking technique was part of a chain of malicious programs, the rest undiscovered, which could have given an attacker full remote access. Apple declined to comment on that prospect.

Advertisement

ZecOps found the Mail app hacking technique was used against a client last year. Avraham described the targeted client as a “Fortune 500 North American technology company,” but declined to name it. They also found evidence of related attacks against employees of five other companies in Japan, Germany, Saudi Arabia, and Israel.

Avraham based most of his conclusions on data from “crash reports,” which are generated when programs fail in mid-task on a device. He was then able to recreate a technique that caused the controlled crashes.

Two independent security researchers who reviewed ZecOps' discovery found the evidence credible, but said they had not yet fully recreated its findings.

Patrick Wardle, an Apple security expert and former researcher for the US National Security Agency, said the discovery “confirms what has always been somewhat of a rather badly kept secret: that well-resourced adversaries can remotely and silently infect fully patched iOS devices.”

Because Apple was not aware of the software bug until recently, it could have been very valuable to governments and contractors offering hacking services. Exploit programs that work without warning against an up-to-date phone can be worth more than $1 million (roughly Rs. 7.6 crores).

While Apple is largely viewed within the cybersecurity industry as having a high standard for digital security, any successful hacking technique against the iPhone could affect millions due to the device's global popularity. In 2019, Apple said there were about 900 million iPhones in active use.

Bill Marczak, a security researcher with Citizen Lab, a Canada-based academic security research group, called the vulnerability discovery “scary.”

“A lot of times, you can take comfort from the fact that hacking is preventable,” said Marczak. “With this bug, it doesn't matter if you've got a PhD in cybersecurity, this will eat your lunch.”

© Thomson Reuters 2020


Is iPhone SE the ultimate 'affordable' iPhone for India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apple, iOS, iPhone, iPad, Cybersecurity, Mail
Advertisement

Related Stories

Popular Mobile Brands
  1. Lenovo Legion Y700 Gen 5 Launched With Snapdragon 8 Elite Gen 5 SoC, 9,000mAh Battery
  2. Realme P4 Lite 5G Launched in India With These Specifications
  3. OnePlus 15T Will be Launched With These Two Gaming-Focused Features
  4. Nothing Phone 4a Pro Review: A Big Leap
  5. OnePlus Watch 4 Could Launch Soon, Listing on EMVCo Site Hints
  6. iQOO Z11, iQOO Z11x to Launch in China On This Date
  7. OnePlus Nord Buds 4 Pro Launched in India With ANC, Up to 54 Hours of Total Playback Time
  8. Samsung Galaxy Forever Offers Easy Upgrade, Return Option in India
  9. Xiaomi Book Pro 14 Debuts With a 72Wh Battery at This Price
  10. Seetha Payanam Now Streaming on OTT: Where to Watch Arjun Sarja's Romantic Road Trip Drama
  1. Xiaomi Watch S5 Launched With 1.48-Inch AMOLED Display, Up to 21 Days of Battery Life: Price, Features
  2. Xiaomi Book Pro 14 Launched With Up to Intel Core Ultra X7 358H Processor, 72Wh Battery: Price, Features
  3. Samsung Galaxy Forever Programme Launched in India for Easy Upgrade with EMI and Return Options
  4. Adobe Introduces Custom Models in Firefly, Expands Access to Project Moonlight
  5. AI Chatbots Tend to Validate Users’ Messages About Suicide and Violence: Study
  6. Polymarket Acquires DeFi Startup Brahma to Strengthen Infrastructure
  7. Meta’s New Facebook Initiative Offers TikTok, YouTube Creators Increased Reach and Guaranteed Pay
  8. Instagram Rolls Out Tap-to-Pause Feature for Reels With More Control Over Playback
  9. Seetha Payanam Now Streaming on OTT: Where to Watch Arjun Sarja’s Romantic Road Trip Drama
  10. Circle Urges UK to Blend MiCA Clarity With US Stablecoin Rules
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.