A vulnerability in the iOS email client allows an attacker to send messages that can trick recipients into providing their Apple credentials while on malicious websites.
The vulnerability has already been reported to Apple since January 15, but Jan Soucek, the researcher who discovered it, says it has not been patched in any of the iOS versions released after version 8.1.2.
PoC published
Apple's mobile operating system, iOS, is currently in stable version 8.3, while 8.4 is in beta development and is only available to registered developers.
Apple has not taken any action to resolve the issue for five months, so the researcher decided to make his findings and proof of concept (PoC), in the hope that this will force the company to speed up the fix.
Vulnerability
Researcher Soucek found that the HTML tag is not ignored by the Email application, which can be exploited to replace the original content in an email message with HTML tags from a remote location under the attacker's control.
In the video he posted to demonstrate the success of the exploit, he shows the Apple homepage emerging from malicious messages.
An email that spoofs the login page can be sent without displaying content from a different website, using the “http-equiv” attribute which provides flexibility and allows the fake login page to be placed in the correct context.
Soucek says that the “vulnerability can be exploited for anything that requires HTML tags that are not supported by Mail.app.”
One way to protect against such an attack is to enable two-factor authentication on your Apple ID.
