
Although Apple is one of the companies that always emphasizes the importance it places on user security, two new zero-day discovered in the built-in email app put more than 2 billion iPhone and iPad.
The vulnerabilities discovered by ZecOps security researchers have been exploited by hackers for at least the last two years to spy on high-end user devices.
The first is an out-of-bounds write bug , while the second flaw is a heap overflow issue according to the researchers' report
To exploit the vulnerabilities, attackers would need to send a specially crafted emailthat consumes a certain amount of memory, causing the app to crash. This would allow attackers to then hack into iOS and take control of them remotely.
The second vulnerability is actually zero-click, meaning that the user does not need to do anything for the attacker to exploit it. Another worrying point is that users have no indication that their devices have been attacked.
According to the researchers, both vulnerabilities they discovered have been found in various Apple devices for the past 8 years and appear to affect the latest version of iOS 13.4.1. The flaws have been widely exploited by malicious actors targeting VIP users such as:
- Employees of Fortune 500 companies in North America
- A journalist in Europe
- A VIP from Germany
- MSSP from Saudi Arabia and Israel
- An executive working at the Japanese transportation company
- An executive working in a Swiss company
The company was informed of the existence of the vulnerabilities and is already preparing a beta version containing a fix for affected devices, which it is expected to present to users of the stable version in the next iOS 13.4.5 update.
