Apple says it is working on a fix for a macOS bug that stored portions of encrypted emails sent via Mail app in an unencrypted form
Jay Peters / The Verge :
Context & Ripple Effects
This macOS Mail flaw sits in a longer line of Apple email-security failures: back in 2015 an iOS Mail bug reported in January let attackers phish iCloud passwords via crafted emails and went months without a fix. The new Catalina bug is quieter but arguably worse in kind — messages users believed were protected by encryption were partially written to disk in plaintext.
What makes the story worth tracking is its resolution arc and recurrence: Apple only confirmed a fix months after the initial report, per follow-up coverage of the Catalina patch arriving in early 2020, and years later the same disclose-wait-patch rhythm reappeared with a Hide My Email flaw exposing users' real addresses, which Apple also left unfixed for roughly a year before patching.
First-order effects
- Users of S/MIME-encrypted Mail on macOS Catalina had portions of sensitive correspondence stored unencrypted on disk, defeating the point of their encryption setup until Apple shipped a patch.
Second-order effects
- Security-conscious buyers — enterprises, lawyers, journalists — get another data point weighing Apple's privacy marketing against its actual patch latency, pressuring Apple to shorten the report-to-fix window rather than acknowledge bugs only under researcher and press pressure.
Third-order effects
- If the Mail and Hide My Email episodes are the pattern rather than exceptions, Apple's privacy differentiation erodes at exactly the layer it claims to own — data protection defaults — and independent researchers become the de facto QA process for features marketed as secure by design.
The trend: Apple's most privacy-critical features keep shipping vulnerabilities that take many months to patch, turning researcher disclosures into the real driver of its security fixes.