/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Apple says it is working on a fix for a macOS bug that stored portions of encrypted emails sent via Mail app in an unencrypted form

Jay Peters / The Verge :

The Verge Jay Peters

Context & Ripple Effects

This macOS Mail flaw sits in a longer line of Apple email-security failures: back in 2015 an iOS Mail bug reported in January let attackers phish iCloud passwords via crafted emails and went months without a fix. The new Catalina bug is quieter but arguably worse in kind — messages users believed were protected by encryption were partially written to disk in plaintext.

What makes the story worth tracking is its resolution arc and recurrence: Apple only confirmed a fix months after the initial report, per follow-up coverage of the Catalina patch arriving in early 2020, and years later the same disclose-wait-patch rhythm reappeared with a Hide My Email flaw exposing users' real addresses, which Apple also left unfixed for roughly a year before patching.

First-order effects

  • Users of S/MIME-encrypted Mail on macOS Catalina had portions of sensitive correspondence stored unencrypted on disk, defeating the point of their encryption setup until Apple shipped a patch.

Second-order effects

  • Security-conscious buyers — enterprises, lawyers, journalists — get another data point weighing Apple's privacy marketing against its actual patch latency, pressuring Apple to shorten the report-to-fix window rather than acknowledge bugs only under researcher and press pressure.

Third-order effects

  • If the Mail and Hide My Email episodes are the pattern rather than exceptions, Apple's privacy differentiation erodes at exactly the layer it claims to own — data protection defaults — and independent researchers become the de facto QA process for features marketed as secure by design.

The trend: Apple's most privacy-critical features keep shipping vulnerabilities that take many months to patch, turning researcher disclosures into the real driver of its security fixes.

Discussion

  • @derekmizak Derek Mizak on x
    #cybersecurity by obscurity is never a good idea. In this case it is a disappointment but also a wake-up call for those who plan security policy. Encrypting storage should be default. https://www.theverge.com/...
  • @jaypeters Jay Peters on x
    macOS can store portions of some encrypted emails sent from Apple Mail as if they were unencrypted. The issue was first reported to Apple on July 29. macOS updates since haven't fixed it, but Apple tells The Verge it will address it in a future software update. https://twitter.co…
  • @campuscodi Catalin Cimpanu on x
    Apple Mail on macOS leaves parts of encrypted emails in plaintext > Sierra to Catalina affected > No official fix available > Hacky hack hack countermeasures available > Apple has known since July https://www.zdnet.com/... https://twitter.com/...