Security firm ZecOps: iOS Mail app's old, unpatched bugs have been exploited against a US Fortune 500 firm, a Japanese telco exec, a journalist in Europe, more
Lily Hay Newman / Wired :
Context & Ripple Effects
iOS Mail's security record was already shaky before this report: a [[a:829996|Mail bug reported in January 2015 let attackers phish iCloud passwords via email and went months without a fix]], and Apple's 2016 emergency patch came only after researchers caught NSO-linked zero-days being aimed at activists like Ahmed Mansoor (the same disclosure cycle that forced iOS 9.3.5).
ZecOps' claim changes the framing from theoretical risk to confirmed operations: bugs in the stock Mail app were not just available but actively used against a US Fortune 500 company, a Japanese telecom executive, and a European journalist — targets consistent with the commercial-spyware customer base documented since the Mansoor targeting, and following Project Zero's 2019 documentation of five iOS exploit chains deployed through hacked websites.
First-order effects
- Apple faces immediate pressure to ship a Mail fix and explain how bugs old enough to be 'unpatched for years' survived its security process while being used in live attacks.
- The named victims — the Fortune 500 firm, the telco executive, the journalist — must treat their devices as compromised and hunt for follow-on intrusion, since Mail-level access typically precedes deeper espionage.
Second-order effects
- Spyware vendors now have proof that Mail is a viable delivery surface alongside the browser chains Project Zero documented, shifting exploit procurement toward core apps that cannot be sandboxed away by user behavior.
- Security-conscious enterprises and executives will weigh disabling or replacing the native Mail client on iPhones, pressuring Apple to harden an app most users assumed was inert infrastructure.
Third-order effects
- If high-value Mail exploitation proves routine, iPhone threat modeling shifts from 'patch quickly' to 'assume long windows of undetected compromise,' boosting demand for mobile forensics firms like ZecOps and pushing regulators toward mandatory disclosure timelines.
- The trajectory from activist targets in 2016 to corporate and media targets now suggests commercial spyware customers are broadening beyond governments chasing dissidents to competitive and corporate espionage.
The trend: iPhone attack surfaces are migrating from one-shot browser exploits toward long-lived core apps like Mail, where bugs can be exploited operationally for years before anyone notices.