/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers say they found two actively exploited iOS 0-days, present since at least iOS 6, including a remote zero-click flaw in Mail; Apple says patch coming

In the summer of 2016, researchers at a digital rights organization and a cybersecurity firm announced they had caught …

VICE Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

This disclosure extends a thread that started with the 2016 discovery of zero-days used to target activists, attributed to malware vendor NSO and patched by Apple in iOS 9.3.5. The new finding raises the stakes: the two flaws have reportedly been present since at least iOS 6, meaning an entire generation of iPhones shipped with an actively exploited remote zero-click hole in Mail.

The arc since then has been one of repeated emergency response — from the 2016 activist-targeting patch to the [[a:971042|2021 disclosure of three zero-days still exploitable in iOS 15 despite being reported to Apple months earlier]] to the December 2023 emergency updates that brought Apple to 20 zero-days patched that year. A flaw this old and this reachable reframes iOS security from isolated incidents to a persistent exploitation problem.

First-order effects

  • Apple must ship a patch for both flaws on its stated timeline, while every user of the stock Mail app is exposed in the interim to remote compromise requiring no click, attachment open, or other interaction.
  • Whoever has been exploiting these flaws in the wild loses two working entry points the moment the update lands, forcing reliance on whatever undisclosed inventory remains.

Second-order effects

  • Commercial spyware operators of the NSO type seen in the 2016 campaign face a thinner exploit market for current iOS versions, pushing up prices for fresh zero-click chains and accelerating churn toward new targets like messaging apps and browsers.
  • Security researchers gain leverage from the demonstrated longevity of these bugs: the 2021 episode showed Apple sitting on reported flaws still live in iOS 15, so coordinated-disclosure deadlines and public pressure around patch latency will intensify.

Third-order effects

  • If the pattern holds — long-lived exploited flaws surfacing years after introduction, followed by emergency fixes — iOS security settles into a permanent cycle where Apple's patch cadence, not any single fix, becomes the real defensive metric users and enterprises track.
  • Sustained zero-click exploitation of core apps strengthens the argument for architectural hardening of default surfaces like Mail, since a vulnerability dating to iOS 6 shows that legacy code paths remain the industry's most durable attack surface.

The trend: iPhone zero-click exploitation is shifting from episodic scandals into a standing arms race between commercial spyware buyers and Apple's emergency-patch machinery.

Discussion

  • @ryanaraine Ryan Naraine on x
    Rumors of in-the-wild 0day attacks against iOS Mail has been persistent for weeks. Zecops drops details https://blog.zecops.com/... https://twitter.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    New: researchers say they caught hackers exploiting a remote zero-click exploit for iPhones in the wild. The bugs are not yet patched, but Apple says it will patch them in the next iOS release. https://www.vice.com/... https://twitter.com/...
  • @adamfowler_it Adam Fowler on x
    @TheRegister Good article, but how did you get to the conclusion that most of us don't have to worry because it's only high level targets? If a patch is coming surely there's a chance they'll look to cash in quick and sell cheaper/more?
  • @antiviruslv @antiviruslv on x
    Researchers are reporting two Apple #iOS 0-day security #vulnerabilities affecting its Mail app on iPhones and iPads. Impacted are iOS 6 and iOS 13.4.1. Apple patched both vulnerabilities in iOS 13.4.5 beta. A final release of iOS 13.4.5 is expected soon. https://threatpost.com/.…
  • @theregister @theregister on x
    Zero-click, zero-day flaw in iOS Mail exploited to hijack VIP smartphones. Apple rushes out beta patch https://www.theregister.co.uk/ ...
  • @viss @viss on x
    oh sweet, zero click 0day for ios devices. https://blog.zecops.com/...
  • @matthew_d_green Matthew Green on x
    The memory usage of these exploit emails is quits large. Does anyone have thoughts about this? https://twitter.com/...
  • @kennwhite Kenn White on x
    - beta patch released by Apple - attack is fairly advanced, but actual exploit appears to be POC-grade - multiple delivery methods including large mail but also multi-part & rich text format hacks - full report, with IOCs and FAQ from @ZecOps: https://blog.zecops.com/... (2/2)
  • @kennwhite Kenn White on x
    Recap on the iOS no-click zero day report: - @ZecOps' forensics indicates targets were people from at least 6 orgs - Heap overflow in default Mail app vulnerable since iPhone 5 (circa 2012) https://www.vice.com/... https://www.wsj.com/... via @bobmcmillan and @lorenzofb (1/2)
  • @lukolejnik Lukasz Olejnik on x
    Zero-click remote iPhone (since iOS 6; 2012) vulnerability? Workaround: do not use Mail app until fix is installed (iOS 13.4.5). This looks rather severe. https://blog.zecops.com/... https://twitter.com/...
  • @wsj @wsj on x
    Sophisticated hackers may be attacking Apple iPhones by exploiting a previously unknown flaw in the smartphone's email software, according to a digital-security company that has investigated the incidents https://www.wsj.com/...
  • @newley Newley Purnell on x
    Targets identified include employees of a telecommunications company in Japan, a large North American firm, technology companies in Saudi Arabia and Israel, a European journalist and an individual in Germany. https://www.wsj.com/... https://twitter.com/...
  • @ildannymoore Daniel Moore on x
    A relatively loud remote zero-click 0day in iOS's default mail client actively used against a diverse, underwhelming set of international targets. This could've been so valuable if used with operational finesse. Some threat actors have a lot of resources to burn. https://twitter.…