Ernst & Young security researchers, along with Jan Soucek, who discovered the vulnerability, have developed a tool capable of generating iCloud password phishing emails by exploiting an unpatched bug that affects millions of Apple users.
Researchers have developed the iOS 8.3 Mail.app inject kit that exploits a bug in Apple's email. It essentially creates a realistic pop-up that looks exactly like Apple's.
Soucek (jansoucek) also reports that Cupertino did not respond when he tried to inform them about the bug in January.
“This bug allows remote HTML content to be loaded, replacing the content of the original email message. JavaScript is disabled in this UIWebView, but it is still possible to develop a page that collects passwords using plain HTML and CSS.”
Phishers using the free tool developed by the researchers can successfully run phishing campaigns, collecting whatever credentials they want. Their victims will only see a pop-up in the iOS Mail app.
Soucek ensures with his tool that http-equiv only targets victims who allow cookies to be installed on their iDevices.
The researcher says it is a better phishing tool than the usual pages that come inside an email message, because it only targets users whose app allows the changes to be made.
Publishing the tool should not be considered malicious, White hat security researchers often publish sophisticated phishing tools for professionals who use them within companies, to train staff in social engineering.
