HomeSecurityHole in the Mail app of iOS 8.3

Hole in the iOS 8.3 Mail app

Mailapp iOS 8.3: A flaw has been found in the iOS 8.3 email client that allows attackers to send deceptive messages with the aim of phishing for credentials used at Apple . The vulnerability has been reported since January, but Jan Soucek , the researcher who discovered it, says that it has not yet been fixed in any version of iOS released after 8.1.2. Five whole months after the report, the popular company has not taken any action to fix it, which is why Soucek decided to make the PoC public in a video, hoping that the company will be forced to make an immediate fix. In this video with the exploit, Soucek shows how the Apple homepage appears through malicious messages. An email that spoofs the login page can be sent without displaying content from another website, by using “ http-equiv “, which allows the fake login page to be placed correctly.iOS 8.3

The researcher states that the hole can be used for anything that requires HTML tags that Mail.app does not support.

To protect yourself from such an attack, you can enable 2-factor authentication on your Apple ID.

Apple's mobile operating system is available in the stable version iOS 8.3, but also in 8.4 in beta - only for registered developers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS