A security researcher said that a vulnerability in Apple's mobile email application could be used to trick users into revealing their iCloud passwords.
Jan Soucek published proof-of-concept code (you can see it by clicking here) that demonstrates how he could send an email to someone with HTML code that resembles the iCloud login pop-up window. Soucek would then receive an email containing the user's password.
The vulnerability allows HTML content to be loaded in an email, which replaces the email message's content. Soucek wrote that he later built a password collector using HTML and CSS. He also published a demonstration video.
He found the bug in January and has reported it to Apple. The bug was not fixed in iOS 8.1.2, «therefore I decided to publish the proof of concept code here,» wrote Soucek . The senior Apple staff did not comment immediately.
Soucek equipped the exploit code so that the fake iCloud authentication window appears only once, which reduces suspicion, he wrote.
Apple has taken measures to strengthen the security of iCloud accounts after the breach of the accounts of many famous personalities that occurred last year.
The celebrities' iCloud accounts may have been accessed after hackers correctly guessed their usernames and passwords, or possibly by correctly answering the security questions that Apple asks if a user has forgotten their password.
It is also possible that the personalities fell victim to the phishing tactic exposed by Soucek, making the incident even more concerning.
With iCloud credentials, it is possible to download the entire content of an account onto a device, including photos, text messages, call logs, address books, calendars and other information, depending on what each person has stored in iCloud.

