Apple Prepares Fix for Actively Exploited iPhone Mail App Vulnerability

Hackers are actively exploiting a severe, zero-click vulnerability in the iPhone's default Mail app to steal sensitive data from targeted victims. Apple is preparing an upcoming software update to patch the bug, which security researchers trace back to 2012.

Security researchers at ZecOps uncover a highly valuable zero-day vulnerability in the iPhone's default Mail app that hackers actively use to steal device data. By sending a specially crafted email, attackers overrun the device's memory and remotely execute malicious code without requiring any interaction from the victim on the latest version of iOS 13. The firm discovers that at least six organizations face targeting from these attacks as far back as 2018, with victims including a U.S.-based Fortune 500 company and a European journalist.

The bug traces all the way back to iOS 6, which first launched in 2012, though macOS Mail users remain unaffected. Because iPhone vulnerabilities are incredibly difficult to find, these zero-day exploits fetch up to $1 million on the black market, meaning only well-resourced threat actors like nation-states typically possess them. While such sophisticated tools are often reserved for tracking criminals or terrorists, governments also frequently use them against journalists, activists, and specific ethnic groups.

Apple currently does not comment on the record, but reports indicate that a fix already exists in a beta version of the software and will roll out to all users in an upcoming update. Until the official patch arrives, security experts advise high-risk individuals to disable the default Mail app entirely to prevent potential data theft. The discovery highlights the persistent threat of state-sponsored cyberattacks against high-profile targets using highly prized exploits.

Read More at the original source →