iOS Mail app bug reported in January lets hackers send phishing emails to steal your iCloud password, no fix yet
Password-flogging phishing tool pwns EVERY iOS Mail app — Cupertino quiet on pop-up of doom — Ernst and Young forensic bod Jan Soucek has created a tool capable …
Context & Ripple Effects
Ernst & Young forensic researcher Jan Soucek has built a tool that turns the iPhone's default Mail client into a credential harvester: a crafted message triggers a password pop-up that harvests iCloud logins, and per the report Apple has shipped no fix since the bug was disclosed in January — Cupertino is staying quiet.
The episode opens a recurring file in Apple security coverage: a developer later showed how malicious apps can fake the native system dialog box to phish for Apple ID passwords, and ZecOps eventually documented old, unpatched iOS Mail bugs being exploited in the wild against a Fortune 500 firm, a Japanese telco executive and a journalist. The 2015 disclosure is where the pattern of stock-app neglect starts showing.
First-order effects
- Every iPhone user relying on the stock Mail app is exposed to phishing messages whose forged prompts can capture iCloud credentials, and Apple — the named party responsible for the patch — has issued nothing in the months since the January report.
- Soucek's working tool lowers the barrier for attackers: the phishing mechanism requires only a specially crafted email delivered through the default client.
Second-order effects
- Apple's silence invites further researcher demonstrations along the same seam between remote content and trusted system UI — the dynamic that resurfaces in later coverage of apps replicating the native password dialog.
- Security teams at enterprises and newsrooms have to defend against a vector inside Apple's own first-party software, where the usual advice of 'install a better client or wait for the vendor patch' offers no immediate relief.
Third-order effects
- ZecOps' later finding that years-unpatched Mail flaws were used against real targets shows how this category matures: vulnerabilities left open in bundled apps convert into actual espionage-style campaigns rather than staying theoretical.
- If Apple keeps patching its preinstalled apps on its own timeline, the structural consequence is that 'secure by default' becomes conditional on first-party update discipline — pushing enterprises and high-risk users toward third-party clients or demanding faster vendor response guarantees.
The trend: Preinstalled iOS apps are emerging as a standing attack surface that Apple patches on its own schedule, not users' or defenders'.