Edison Mail says it has “rolled back” an iOS app update that gave a “small percentage” of users full access to other users' email accounts
Edison Mail is one of the more popular third-party email applications for iPhone, iPad, and Mac, but an apparent bug in the service is raising major privacy concerns.
Context & Ripple Effects
Edison Mail enters this incident with its data practices already under a spotlight: a February investigation detailed how popular email apps including Edison scrape users' inboxes to power market research products. Now the company says it has rolled back an iOS update whose bug handed a "small percentage" of users full access to other people's email accounts — the second time this year the app has been at the center of an email-privacy story.
The episode also lands amid a broader run of mail-client security failures on Apple platforms, from the old unpatched iOS Mail flaws ZecOps found being exploited against a Fortune 500 firm and others to Apple's own Hide My Email leak fixed years later.
First-order effects
- Users caught in the "small percentage" had their full mailboxes readable by strangers through no action of their own, and Edison has responded by pulling the update rather than patching forward.
- For Edison Mail, the rollback compounds reputational damage from the earlier inbox-scraping report — the same month it was named in VICE's coverage of apps harvesting email for market research.
Second-order effects
- Third-party email clients now compete against Apple's native Mail under a trust deficit, even though Apple's own stack carries comparable baggage — the ZecOps-exploited iOS Mail bugs and the later Hide My Email vulnerability show first-party software fails here too.
- Enterprise and privacy-conscious buyers evaluating mail clients gain fresh ammunition to demand audit rights and access-control assurances before granting OAuth-level account permissions.
Third-order effects
- If authorization bugs like this keep surfacing across both third-party and first-party clients, mailbox access itself becomes the regulated surface — pushing toward tighter permission scoping and external security review for anything holding full account credentials.
- The pattern echoes Apple's own iOS 13 bug that mistakenly granted third-party keyboards full access, suggesting platform-level access-granting mechanisms, not any single vendor's code, are the recurring weak point.
The trend: Email clients — third-party and first-party alike — are accumulating access-control failures fast enough that full-account permissions are becoming a regulatory and procurement battleground rather than a routine integration detail.