Mobile menu toggle

iOS mail exploit might let phishers snatch your Apple ID credentials

By

A new day, a new iOS bug...
A new day, a new iOS bug...
Photo: Jim Merithew/Cult of Mac

iOS security researchers Jan Souček has discovered a new bug in iOS’s mail client that could trick users into accidentally giving attackers their AppleID and password.

The Mail app exploit was discovered at the beginning of 2015, and Apple’s engineers were quickly notified of its existence, but a fix for the bug hasn’t been released in any of the updates following iOS 8.1.2. According to Souček, the bug allows remote HTML content to be loaded, making it possible to build a password collector that looks just like an iCloud sign-in prompt.

Here’s a video of the bug in action:

In a GitHub repo detailing his discovery, Souček says the bug was filed under Radar #19479280 back in January. Soucek used the exploit to create a tool capable of generating iCloud password phishing emails, but it could be customized by phishers to pilfer passwords from other services as well.

We reached out to Apple for comment on whether or not a fix is in the works, but haven’t received a comment at this time.

Source: TheRegister

  • Subscribe to the Newsletter

    Our daily roundup of Apple news, reviews and how-tos. Plus the best Apple tweets, fun polls and inspiring Steve Jobs bons mots. Our readers say: "Love what you do" -- Christi Cardenas. "Absolutely love the content!" -- Harshita Arora. "Genuinely one of the highlights of my inbox" -- Lee Barnett.

5 responses to “iOS mail exploit might let phishers snatch your Apple ID credentials”

  1. wintermute2011 says:

    Correct me if I am wrong, but this is not a bug but merely a function of ALL modern email viewers that allow the viewing of remote content. Apple at least gives us the option to turn off “Load remote content in messages” in Mail preferences. Smart users will be sure to disallow automatic loading of such remote content by setting their preferences accordingly.

  2. Code Monkey says:

    Yet another “bug” report that really isn’t a “bug” … great job CoM. NOT. Just turn off “Load remote content in messages” problem solved.

  3. digitaldumdum says:

    Click-bait, fear-mongering non-news. (yawn)

  4. Roxy Balboa says:

    I would first water board these so called security experts.

  5. Dimebag says:

    I had something similar without the email confirmation happened to me on yahoo. Should I change my password?

Leave a Reply