Apple says it is working on a fix for a macOS bug that stored portions of encrypted emails sent via Mail app in an unencrypted form
Jay Peters / The Verge :
Context & Ripple Effects
This report lands mid-pattern rather than as a one-off: Mail has been a recurring weak point in Apple's privacy story, from the 2015 iOS Mail bug that let phishing emails harvest iCloud passwords to today's disclosure that macOS stored portions of encrypted messages in plaintext. The related coverage also shows how these episodes resolve — slowly.
The eventual outcome is already visible in the archive: Apple shipped a fix for this exact Catalina bug only after months, per the follow-up confirming the encrypted-email snippets were patched. The same long disclosure-to-fix cadence reappears years later with the Hide My Email flaw reported in June 2025 that went unfixed until July 2026.
First-order effects
- Users who send encrypted mail through the macOS Mail app — the audience encryption exists to protect — have message content sitting unencrypted in local storage right now, while Apple works on a fix it has not yet shipped.
Second-order effects
- Security researchers now have a demonstrated playbook: probe Apple's Mail-adjacent tools, disclose publicly, and wait out a fix cycle measured in months — a dynamic the Hide My Email saga repeats almost beat-for-beat.
Third-order effects
- If the pattern holds, each plaintext-leak finding erodes the practical value of Apple's device-side encryption promises, pushing high-sensitivity users toward third-party encrypted clients and making Apple's patch latency itself a reputational metric.
The trend: Apple's privacy positioning keeps being stress-tested by Mail-family bugs where supposedly protected data ends up exposed, with fixes consistently trailing researcher disclosures by months.