Apple seems to have fixed a macOS Catalina bug, first reported in July, that caused snippets of encrypted emails sent via the Mail app to be stored unencrypted
Jay Peters / The Verge :
Context & Ripple Effects
This closes a seven-month loop: the unencrypted-storage bug in macOS Catalina's Mail app was first reported in July 2019, and Apple only publicly committed to a fix in November 2019, saying it was working on one. Today's report is the resolution of that promise.
The story fits a recurring shape in Apple's security record covered here: macOS flaws surfaced by outside parties — Microsoft reported the Gatekeeper bypass Apple patched in late 2022 — and privacy-adjacent bugs like the Hide My Email exposure that leaked real addresses despite researchers flagging them well before the fix.
First-order effects
- Catalina users who send encrypted email through the Mail app get the actual fix: message snippets are no longer written to disk in plaintext, closing the local-exposure window that existed since the July 2019 report.
Second-order effects
- The long gap between the July report and the shipped fix gives security researchers a fresh data point on Apple's patch latency for privacy bugs — the same latency pattern visible in the Hide My Email disclosure, where a June-reported flaw went unfixed for over a year before repair.
Third-order effects
- If outside-reported privacy bugs keep taking months to resolve, scrutiny shifts from whether Apple ships encryption to how quickly it remediates when its own implementations leak plaintext — making fix turnaround itself a measure of the company's privacy posture.
The trend: Apple's privacy features are increasingly judged not by their design but by how fast the company patches the implementation bugs researchers find in them.