/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Apple says it is working on a fix for a macOS bug that stored portions of encrypted emails sent via Mail app in an unencrypted form

Jay Peters / The Verge :

The Verge Jay Peters

Context & Ripple Effects

This report lands mid-pattern rather than as a one-off: Mail has been a recurring weak point in Apple's privacy story, from the 2015 iOS Mail bug that let phishing emails harvest iCloud passwords to today's disclosure that macOS stored portions of encrypted messages in plaintext. The related coverage also shows how these episodes resolve — slowly.

The eventual outcome is already visible in the archive: Apple shipped a fix for this exact Catalina bug only after months, per the follow-up confirming the encrypted-email snippets were patched. The same long disclosure-to-fix cadence reappears years later with the Hide My Email flaw reported in June 2025 that went unfixed until July 2026.

First-order effects

  • Users who send encrypted mail through the macOS Mail app — the audience encryption exists to protect — have message content sitting unencrypted in local storage right now, while Apple works on a fix it has not yet shipped.

Second-order effects

  • Security researchers now have a demonstrated playbook: probe Apple's Mail-adjacent tools, disclose publicly, and wait out a fix cycle measured in months — a dynamic the Hide My Email saga repeats almost beat-for-beat.

Third-order effects

  • If the pattern holds, each plaintext-leak finding erodes the practical value of Apple's device-side encryption promises, pushing high-sensitivity users toward third-party encrypted clients and making Apple's patch latency itself a reputational metric.

The trend: Apple's privacy positioning keeps being stress-tested by Mail-family bugs where supposedly protected data ends up exposed, with fixes consistently trailing researcher disclosures by months.

Discussion

  • @derekmizak Derek Mizak on x
    #cybersecurity by obscurity is never a good idea. In this case it is a disappointment but also a wake-up call for those who plan security policy. Encrypting storage should be default. https://www.theverge.com/...
  • @jaypeters Jay Peters on x
    macOS can store portions of some encrypted emails sent from Apple Mail as if they were unencrypted. The issue was first reported to Apple on July 29. macOS updates since haven't fixed it, but Apple tells The Verge it will address it in a future software update. https://twitter.co…
  • @campuscodi Catalin Cimpanu on x
    Apple Mail on macOS leaves parts of encrypted emails in plaintext > Sierra to Catalina affected > No official fix available > Hacky hack hack countermeasures available > Apple has known since July https://www.zdnet.com/... https://twitter.com/...