/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

iOS Mail app bug reported in January lets hackers send phishing emails to steal your iCloud password, no fix yet

Password-flogging phishing tool pwns EVERY iOS Mail app  —  Cupertino quiet on pop-up of doom  —  Ernst and Young forensic bod Jan Soucek has created a tool capable …

The Register Darren Pauli

Context & Ripple Effects

Ernst & Young forensic researcher Jan Soucek has built a tool that turns the iPhone's default Mail client into a credential harvester: a crafted message triggers a password pop-up that harvests iCloud logins, and per the report Apple has shipped no fix since the bug was disclosed in January — Cupertino is staying quiet.

The episode opens a recurring file in Apple security coverage: a developer later showed how malicious apps can fake the native system dialog box to phish for Apple ID passwords, and ZecOps eventually documented old, unpatched iOS Mail bugs being exploited in the wild against a Fortune 500 firm, a Japanese telco executive and a journalist. The 2015 disclosure is where the pattern of stock-app neglect starts showing.

First-order effects

  • Every iPhone user relying on the stock Mail app is exposed to phishing messages whose forged prompts can capture iCloud credentials, and Apple — the named party responsible for the patch — has issued nothing in the months since the January report.
  • Soucek's working tool lowers the barrier for attackers: the phishing mechanism requires only a specially crafted email delivered through the default client.

Second-order effects

  • Apple's silence invites further researcher demonstrations along the same seam between remote content and trusted system UI — the dynamic that resurfaces in later coverage of apps replicating the native password dialog.
  • Security teams at enterprises and newsrooms have to defend against a vector inside Apple's own first-party software, where the usual advice of 'install a better client or wait for the vendor patch' offers no immediate relief.

Third-order effects

  • ZecOps' later finding that years-unpatched Mail flaws were used against real targets shows how this category matures: vulnerabilities left open in bundled apps convert into actual espionage-style campaigns rather than staying theoretical.
  • If Apple keeps patching its preinstalled apps on its own timeline, the structural consequence is that 'secure by default' becomes conditional on first-party update discipline — pushing enterprises and high-risk users toward third-party clients or demanding faster vendor response guarantees.

The trend: Preinstalled iOS apps are emerging as a standing attack surface that Apple patches on its own schedule, not users' or defenders'.