Skip to main content

Massive iPhone security flaw left millions of phones vulnerable to hacks

 

Over half a billion iPhones are vulnerable to hackers, and iPads are susceptible, too — and Apple is still working to deploy its fix.

Recommended Videos

The issue — which was discovered by cybersecurity company ZecOps exec Zuk Avraham — lies with Apple’s Mail app, which leaves devices vulnerable to hackers, according to Reuters.

Please enable Javascript to view this content

Avraham found a malicious program was exploiting the bug as far back as January 2018, though he’s not sure who was behind the program. He said iPhone owners who were affected were sent a blank email message that crashed the app and forced a reset.

Owners didn’t even have to open the message for the crash to happen, according to The Wall Street Journal. The Mail app downloading it was enough. Hackers could then access the device’s photos, contact, and other data. The vulnerability also left the Mail app susceptible to hackers, including the ability to see private messages.

Avraham doesn’t believe many people have been targeted by the malicious program. Apple said it’s fixed the issue, but it hasn’t yet widely deployed the patch via an update yet.

“Apple takes all reports of security threats seriously,” an Apple spokesperson said in an email Friday to Digital Trends. “We have thoroughly investigated the researcher’s report and, based on the information provided, have concluded these issues do not pose an immediate risk to our users. The researcher identified three issues in Mail, but alone they are insufficient to bypass iPhone and iPad security protections, and we have found no evidence they were used against customers. These potential issues will be addressed in a software update soon. We value our collaboration with security researchers to help keep our users safe and will be crediting the researcher for their assistance.”

Though Apple often touts the security of its products, this isn’t the first vulnerability researchers have found this year. In February, software developers found a flaw in Apple iOS’s copy-and-paste system. It affected both iPhones and iPads.

If you hit copy on some text on your device, it would assume you wanted to paste it into the next app you open. But if you accidentally hit copy and opened a different app, it would still be able to access whatever you copied. Essentially, any app or widget would be able to “see” whatever you had copied, if you opened it right after.

Tommy Mysk, one of the developers who found the problem, told Digital Trends that you can help combat the issue by disabling Universal Clipboard on your device.

If you’re wary about having the Mail app on your iPhone or iPad while waiting for Apple to deploy an update for the issue, you can always delete it.

Patrick Wardle, a security researcher at Jamf Software LLC, told the Wall Street Journal that’s probably unnecessary, as the malicious program seems very limited in reach at this point.

Jenny McGrath
Former Digital Trends Contributor
Jenny McGrath is a senior writer at Digital Trends covering the intersection of tech and the arts and the environment. Before…
Apple just patched a security flaw left users open to phishing attacks
A person holding the Apple iPhone 16 Pro Max.

Apple just shared news that a new security update is available that patches a critical vulnerability in the Apple Password App. If you haven't yet updated your phone to the latest version of iOS, now's a good time — it will prevent you from falling victim to previously unknown security flaws.

The security flaw allowed bad actors to access stored usernames and passwords. The Apple Password App makes it easy to quickly log in to a website using stored credentials, but it should only work over a secured network; in other words, the URL should begin with "HTTPS." Security researchers first discovered the problem when more than 130 insecure websites (those that only used HTTP) had connected with the Password App.

Read more
Apple could be forced to make major changes to how your iPhone works
The back of the Apple iPhone 16 Pro Max.

Apple is facing yet another landmark push in Europe that could open some of the signature features of its ecosystem. The European Commission has today detailed a couple of broad interoperability measures that Apple must follow, in order to oblige with the Digital Markets Act (DMA) guidelines.
These measures cover a total of nine connectivity features available on iPhones, covering everything from smartwatches to headphones. The idea is to give developers access to the same set of advanced features — such as immersive notifications on watches and quick pairing for peripherals — that is locked to Apple’s own devices.
“The specification decisions are legally binding,” says the regulatory body, adding that interoperability is “key to opening up new possibilities for third parties to develop innovative products and services on Apple's gatekeeper platforms.”

Hello, AirDrop alternatives!

Read more
I’ve used the iPhone 16 Pro Max for 6 months. Here’s why I love it
The back of the Apple iPhone 16 Pro Max.

I bought the Apple iPhone 16 Pro Max when it was announced and have used it every day since then, racking up six months of use, and yet I’ve written very little about it. It’s time to change that, explain why it is technically my only “permanent” phone, and why I think it’s superb.
How I use my iPhone

I have two SIM cards. One is my “main” SIM card which is attached to the phone number I use, and the other is all about data, and they both live in different phones. My main SIM is switched in and out of review Android phones all the time, while the SIM I use mostly for data only lives in my Apple iPhone. They’re both always with me, and since September 2024 I’ve used the Apple iPhone 16 Pro Max alongside whatever Android phone I’m reviewing.

Read more