Major Apple security flaws leave iPhone and iPad devices open to attack

(Image credit: Shutterstock / Neirfy)

Security researchers have uncovered serious vulnerabilities in Apple’s native Mail application for iPhone and iPad devices that could allow hackers to scrape personal information without the victim knowing.

One of the flaws is classified as a remote zero-click, meaning the victim is infected without any interaction with a malicious download or website. In this instance, the device is infected when the user opens a rigged email delivered by the hacker.

The bugs were discovered by US-based security firm ZecOps, which published a report on Wednesday that states “with high confidence” that the newly discovered flaws have been widely exploited in the wild.

According to the report, the bugs went unnoticed for the best part of a decade, first appearing in Apple’s Mail application with iOS 6, released in 2012.

Apple security flaws

Although Apple is widely praised for its excellent digital security standards and watertight code, its devices are not invulnerable to attack.

The newly discovered flaws are labeled as zero-days (or 0-days), which means Apple was unaware of their existence and therefore powerless to prevent their exploitation. This makes the exploits highly valuable to malicious actors on underground markets - especially given the relative rarity of zero-days affecting Apple devices.

ZecOps claims it verified the flaws in a controlled lab setting after customers reported unusual device failures. The firm also reportedly uncovered evidence the exploits have been used to assault multiple high-profile targets, including employees of a Fortune 500 company and an executive at a Japanese telecoms firm.

“We are aware of multiple triggers in the wild that happened starting from Jan 2018, on iOS 11.2.2...It is possible that the attackers were using this vulnerability even earlier. We believe these attacks are correlative with at least one nation-state threat operator or a nation-state that purchased the exploit from a third-party researcher,” wrote ZecOps.

The company reported its finding to Apple at the end of March, with a quiet patch for both vulnerabilities issued for the beta version on April 15/16.

“To mitigate these issues - you can use the latest beta available. If using a beta version is not possible, consider disabling Mail application and use Outlook or Gmail that are not vulnerable,” ZecOps advised.

Apple did not respond immediately to our request for comment, but the firm is expected to roll out a widespread fix for the millions of affected devices in due course.

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection