iOS Mail has 'critical' security flaws

(Image credit: StockSnap/Pixabay)

Germany's federal cybersecurity agency has issued a warning urging all iOS users to install Apple's latest security updates which patch two zero-click security vulnerabilities that impact the company's default email app.

The vulnerabilities were first discovered by the US-based security firm ZecOps which found that they were being actively exploited in attacks targeting iOS users since at least January of 2018. Apple has acknowledged the security flaws though the company says it has found “no evidence they were used against customers”.

In its warning, BSI (Bundesamt für Sicherheit in der Informationstechnik) stressed the importance of installing the updates immediately, saying:

“Apple has released security updates with iOS 12.4.7, iOS 13.5 and iPadOS 13.5 that fix the vulnerabilities for all affected iOS versions. Due to the criticality of the vulnerabilities, the BSI recommends that the respective security update be installed on all affected systems immediately.”

No-click vulnerabilities

Both of the security flaws affecting Apple's Mail app are no-click vulnerabilities which result from a memory consumption issue and they can be triggered after the app processes a maliciously crafted message. The first vulnerability, tracked as CVE-2020-9819, could lead to heap corruption while the second vulnerability, tracked as CVE-2020-9818, may lead to unexpected memory modification or application termination.

Fortunately Apple addressed the flaws with the release of iOS 13.5 and iPadOS 13.5 which offer improved memory handling and bounds checking. The vulnerabilities affect iPhone 6S and later, iPad Air 2 and later, iPad mini 4 and later and the iPod touch 7th generation, according to the iOS 13.5 security release notes.

In a blog post, ZecOps explained how a nation-state threat operator leveraged the vulnerabilities to attack high-profile targets, saying:

“We believe that these attacks are correlative with at least one nation-state threat operator or a nation-state that purchased the exploit from a third-party researcher in a Proof of Concept (POC) grade and used ‘as-is’ or with minor modifications (hence the 4141..41 strings). While ZecOps refrain from attributing these attacks to a specific threat actor, we are aware that at least one ‘hackers-for-hire’ organization is selling exploits using vulnerabilities that leverage email addresses as a main identifier.”

While high-profile targets are the most at risk, it is still highly recommended that all iOS users install Apple's latest security updates to avoid falling victim to any potential attacks that exploit the two vulnerabilities.

Via BleepingComputer

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Marvel Rivals
Marvel Rivals will get two new hero skins for Moon Knight and Black Panther this week meaning I'll now need to farm even more Units
Nvidia app
Tired of manually optimizing your games? Nvidia's new G-Assist could save you time