A newly disclosed iPhone vulnerability gives hackers yet another reason to love email.
According to the San Francisco-based security firm ZecOps,Secret Sex Society (2018) bad actors have discovered a way to attack iOS devices via their default email app. And here's the real kick to the guts: In some cases, you don't even have to be tricked into opening the email. The damage is done simply by your phone downloading the malicious email in the background.
ZecOps published details of the vulnerability on Monday, claiming it has seen the attack "widely exploited in the wild." In other words, ZecOps is saying this isn't just some theoretical bug. Rather, people have actually used it in targeted attacks. The vulnerability affects, to some degree, every version of Apple's operating system from iOS 6 and up.
"The vulnerability allows remote code execution capabilities and enables an attacker to remotely infect a device by sending emails that consume significant amount of memory," explains ZecOps. "The vulnerability can be triggered before the entire email is downloaded, hence the email content won’t necessarily remain on the device."
Phones running iOS 13 are particularly vulnerable, as they reportedly don't even need to open the email for it to do its work. If you're running iOS 12, you're a tad bit better off — you have to click the email first, but your phone is ultimately still at risk if you do so.
We reached out to Apple to both confirm ZecOps report and to determine when, if ever, it plans to issue a patch. Apple confirmed that a vulnerability in Mail is patched in the iOS 13.4.5 beta, which is out now, and will be included in an upcoming software update.
At present, assuming you're not running a beta version of iOS, ZecOps says there is no way to prevent this attack other than to disable the default iOS mail app.
So, should you actually be worried about this? Well, that depends. Are you someone with valuable information that a nation-state might want a piece of? If so, then possibly.
Victims of this attack, claims ZecOps, include "individuals from a Fortune 500 organization in North America," "an executive from a carrier in Japan," "a VIP from Germany," "[managed security service providers] from Saudi Arabia and Israel," and "a Journalist in Europe."
SEE ALSO: As coronavirus spreads, yet another company brags about tracking you
In other words, your average Joe doesn't need to stress about this too much.
Still, it's worth keeping in mind that no operating system is completely hack-proof. And yes, that even includes Apple's. Oh yeah, and it also serves as a stark reminder that you should always make sure your phone is running the latest version of iOS — whether you're an average Joe or not.
Topics Apple Cybersecurity iOS iPhone
NYT mini crossword answers for September 18Best activity tracker deal: Get the Fitbit Google Ace for $200Best gaming deal: Pay just $34 for 3 months of Xbox Game Pass UltimateBayern Munich vs. Dinamo Zagreb 2024 livestream: Watch Champions League for freeHinge launches 'Your Turn Limits' featureJuventus vs. PSV 2024 livestream: Watch Champions League liveGoogle searches can now sniff out details on AIMrBeast, Logan Paul and KSI launch Lunchables rival LunchlyOctober Prime Day 2024: How to find the best dealsFree Kindle Unlimited: 3 months free (UK)BOYNEXTDOOR talk fan edits, goReal Madrid vs. Stuttgart 2024 livestream: Watch Champions League for freeLos Angeles Sparks vs. Minnesota Lynx 2024 livestream: Watch live WNBABest gaming deal: Pay just $34 for 3 months of Xbox Game Pass UltimateWhen does October Prime Day start? The dates are out.Chicago Sky vs. Atlanta Dream 2024 livestream: Watch live WNBAPS6 rumor: Intel reportedly rejected for the nextWordle today: The answer and hints for September 17Best activity tracker deal: Get the Fitbit Google Ace for $200Chicago Sky vs. Atlanta Dream 2024 livestream: Watch live WNBA 25 best TV comedies on Max right now How to watch WVU vs. UNC football livestreams: kickoff time, streaming deals, and more One Word: Bonkers by Harry Dodge Ode to Rooftops by Jessi Jezewska Stevens How to watch Texas State vs. Rice football livestreams: kickoff time, streaming deals, and more What Men Have Told Me by Adrienne Miller On the Timeless Music of McCoy Tyner by Craig Morgan Teicher The 20 best British TV shows of 2023 W. H. Auden Was a Messy Roommate by Seamus Perry Mickey Mouse is finally, kind of, becoming public domain Whiting Awards 2020: Genya Turovskaya, Poetry Harry Mathews’s Drifts and Returns by Daniel Levin Becker Louisville vs. USC livestream: Holiday Bowl kickoff time, streaming deals, and more The Photographer and the Ballerina by The Paris Review I've used iPhone 15 Pro Max for 2 months: 5 game The Paris Review Crossword by Adrienne Raphel On Minor Feelings by Cathy Park Hong Long Weekend by Michael DeForge National Treasure, Elizabeth Spencer by Allan Gurganus Redux: Pull the Language in to Such a Sharpness by The Paris Review
2.7714s , 10133.5234375 kb
Copyright © 2025 Powered by 【Secret Sex Society (2018)】,Defense Information Network