A newly disclosed iPhone vulnerability gives hackers yet another reason to love email.
According to the San Francisco-based security firm ZecOps,China Archives bad actors have discovered a way to attack iOS devices via their default email app. And here's the real kick to the guts: In some cases, you don't even have to be tricked into opening the email. The damage is done simply by your phone downloading the malicious email in the background.
ZecOps published details of the vulnerability on Monday, claiming it has seen the attack "widely exploited in the wild." In other words, ZecOps is saying this isn't just some theoretical bug. Rather, people have actually used it in targeted attacks. The vulnerability affects, to some degree, every version of Apple's operating system from iOS 6 and up.
"The vulnerability allows remote code execution capabilities and enables an attacker to remotely infect a device by sending emails that consume significant amount of memory," explains ZecOps. "The vulnerability can be triggered before the entire email is downloaded, hence the email content won’t necessarily remain on the device."
Phones running iOS 13 are particularly vulnerable, as they reportedly don't even need to open the email for it to do its work. If you're running iOS 12, you're a tad bit better off — you have to click the email first, but your phone is ultimately still at risk if you do so.
We reached out to Apple to both confirm ZecOps report and to determine when, if ever, it plans to issue a patch. Apple confirmed that a vulnerability in Mail is patched in the iOS 13.4.5 beta, which is out now, and will be included in an upcoming software update.
At present, assuming you're not running a beta version of iOS, ZecOps says there is no way to prevent this attack other than to disable the default iOS mail app.
So, should you actually be worried about this? Well, that depends. Are you someone with valuable information that a nation-state might want a piece of? If so, then possibly.
Victims of this attack, claims ZecOps, include "individuals from a Fortune 500 organization in North America," "an executive from a carrier in Japan," "a VIP from Germany," "[managed security service providers] from Saudi Arabia and Israel," and "a Journalist in Europe."
SEE ALSO: As coronavirus spreads, yet another company brags about tracking you
In other words, your average Joe doesn't need to stress about this too much.
Still, it's worth keeping in mind that no operating system is completely hack-proof. And yes, that even includes Apple's. Oh yeah, and it also serves as a stark reminder that you should always make sure your phone is running the latest version of iOS — whether you're an average Joe or not.
Topics Apple Cybersecurity iOS iPhone
Scientists discover ancient Greenland shark in a really strange placeBlizzard's Hearthstone to return to China on September 25 · TechNodeIrreversible space rock damage won't stop the Webb telescope from exceeding expectations5 Copilot AI features that are on by default in Microsoft productsWatch NASA's megarocket ace its thrust test before spaceflightBest flight deal: Up to 50% off Southwest Airlines faresLarge language models are rubbish at elementary level math · TechNodeShop the MacBook Pro M3 for $200 off at Best BuyCharli xcx's 'brat' turns the internet lime greenXpeng to contribute to all Volkswagen EVs in China starting 2026 · TechNodeGet the Marshall Major IV headphones for under $100Dogs are smarter than you think, scientists findNASA scientists discover humanNASA astronauts show new way to take out space trashMediaTek develops ArmBest tablet deal: The Samsung Galaxy Tab S9 FE+ is just $489.99 at AmazonMainland Chinese iPhone users unable to access Apple Intelligence after AI update · TechNodeSpaceX just launched South Korea's first mission to the MoonHuawei reportedly sees $1.4 billion sales from car business · TechNodeNASA spotted two giant asteroids flying past Earth Samsung Galaxy Fit is now available in the U.S. for $99 Byton’s massive 48 Well, someone transformed her fiancé's car into a chicken nugget Quintessentially Canadian video shows peckish moose licking salt off car Google Calendar service restored after 3 People are waiting up to 10 hours for new Harry Potter ride at Universal This remarkable Greenland photo highlights extreme Arctic melting Black Lives Matter website hit with more than 100 DDoS attacks this year Chrissy Teigen enlists stand Some YouTube TV Subscribers will get Showtime for free Nintendo confirms Mr. Resetti lost his job thanks to 'Animal Crossing: New Horizons' Drone captures badass killer whales killing a shark like it's NBD 'John Wick Hex' creator Mike Bithell talks unusual prequel: Interview The guy who reviews London chicken shops made a glorious TV appearance Apple will release two 5G 'Game of Thrones' star Lena Headey reveals how she really felt about Cersei's death 'Watch Dogs: Legion' is missing fat bodies because of tech limitations Someone wanted a Mariah Carey birthday cake. They got Marie Curie instead. Nuro autonomous vehicles will deliver Domino's pizza Google Calendar scam adds malicious links to your schedule
1.7598s , 10131.640625 kb
Copyright © 2025 Powered by 【China Archives】,Wisdom Convergence Information Network