Germany's federal cybersecurity agency today urged iOS users to immediately install the iOS and iPadOS security updates that Apple released on May 20 to patch two zero-click security vulnerabilities that have been actively exploited affecting the default email app.
"Due to the criticality of the vulnerabilities, BSI recommends the immediate installation of the corresponding security update on all affected systems," BSI said.

Startup ZecOps revealed the bugs after discovering ongoing attacks targeting iOS users since at least January 2018.
The two zero-click vulnerabilities are a memory consumption issue reported as CVE-2020-9819 that can lead to “heap corruption” and an “out-of-bounds write” issue reported as CVE-2020-9818, which can lead to unexpected memory or application termination – both were triggered after the Mail app processed a malicious mail message.
The MailDemon security flaws were addressed by Apple with the release of iOS 13.5 and iPadOS 13.5, which come with improved memory handling and limit checking.
“We believe these attacks are associated with at least one nation-state threat actor or a nation-state that purchased the exploit from a third-party researcher at Proof of Concept (POC) level and used it ‘as is’ or with minor modifications,” ZecOps said at the time.
Fortunately, the attacks reported by ZecOps were directed at high-profile targets, meaning regular users won't be directly targeted until exploits for the two bugs fall into the hands of threat actors with less ambitious goals.
The bugs affect devices running iOS 3.1.3 and later
According to the iOS 13.5 security release notes, the vulnerabilities discovered by ZecOps affect the iPhone 6s and later, the iPad Air 2 and later, the iPad mini 4 and later, and the 7th generation iPod touch.
Based on ZecOps' analysis of the two bugs, all devices running iOS 3.1.3 to 13.4.1 are exposed to potential attacks that would enable remote code execution on compromised iPhone and iPad devices and provide access to leak, edit, and delete emails.
As the founder and CEO of ZecOps shared, “these vulnerabilities have also existed since the first iPhone (iPhone 1 / iPhone 2G) and at least since iOS 3.1.3.”
In an official statement released after the ZecOps findings were revealed, Apple disputed the researchers' claims of ongoing attacks:
Apple takes all reports of security threats seriously. We have thoroughly investigated the researcher’s report and, based on the information provided, we have concluded that these issues do not pose an immediate risk to our users. The researcher identified three issues in Mail, but they alone are not sufficient to bypass iPhone and iPad security protections, and we have not found evidence that they were used against customers. These potential issues will be addressed in a software update. We value our collaboration with security researchers to keep our users safe and will credit the researcher for their assistance.
