/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Edison Mail says it has “rolled back” an iOS app update that gave a “small percentage” of users full access to other users' email accounts

Edison Mail is one of the more popular third-party email applications for iPhone, iPad, and Mac, but an apparent bug in the service is raising major privacy concerns.

9to5Mac Chance Miller

Context & Ripple Effects

Edison Mail enters this incident with its data practices already under a spotlight: a February investigation detailed how popular email apps including Edison scrape users' inboxes to power market research products. Now the company says it has rolled back an iOS update whose bug handed a "small percentage" of users full access to other people's email accounts — the second time this year the app has been at the center of an email-privacy story.

The episode also lands amid a broader run of mail-client security failures on Apple platforms, from the old unpatched iOS Mail flaws ZecOps found being exploited against a Fortune 500 firm and others to Apple's own Hide My Email leak fixed years later.

First-order effects

  • Users caught in the "small percentage" had their full mailboxes readable by strangers through no action of their own, and Edison has responded by pulling the update rather than patching forward.
  • For Edison Mail, the rollback compounds reputational damage from the earlier inbox-scraping report — the same month it was named in VICE's coverage of apps harvesting email for market research.

Second-order effects

  • Third-party email clients now compete against Apple's native Mail under a trust deficit, even though Apple's own stack carries comparable baggage — the ZecOps-exploited iOS Mail bugs and the later Hide My Email vulnerability show first-party software fails here too.
  • Enterprise and privacy-conscious buyers evaluating mail clients gain fresh ammunition to demand audit rights and access-control assurances before granting OAuth-level account permissions.

Third-order effects

  • If authorization bugs like this keep surfacing across both third-party and first-party clients, mailbox access itself becomes the regulated surface — pushing toward tighter permission scoping and external security review for anything holding full account credentials.
  • The pattern echoes Apple's own iOS 13 bug that mistakenly granted third-party keyboards full access, suggesting platform-level access-granting mechanisms, not any single vendor's code, are the recurring weak point.

The trend: Email clients — third-party and first-party alike — are accumulating access-control failures fast enough that full-account permissions are becoming a regulatory and procurement battleground rather than a routine integration detail.

Discussion

  • @edison_apps Edison on x
    We have resolved the recent security issue in Edison mail for iOS and secured all potentially impacted accounts. We apologize to all and are fixing our processes so this does not happen again. Learn more here: https://medium.com/...
  • @backlon Dieter Bohn on x
    Forthwith, a comprehensive list of cloud services I feel comfortable granting full access to my email account: 1. The original email provider, e.g. gmail or outlook. End of list. https://twitter.com/...
  • @_am1t Amit Gawande on x
    Unauthorized access to “small percentage” of users does not reduce the sheer gravity of the bug. Email access can cause havoc. https://twitter.com/...
  • @davidbyttow David Byttow on x
    This is why you don't give hosted services access to your email - ever. I have a story from Google+ days where we (me) inadvertently introduced a near catastrophic privacy bug caused by a single line of misplaced code (early return). Luckily, we caught it. https://9to5mac.com/...
  • @cabel @cabel on x
    What an interesting butterfly effect Apple wants to preserve your battery life > email clients can't check in the background > email clients set up servers to store credentials and check email to push notify you of new email > everyone's email now exposed to huge security vector
  • @peteskomoroch @peteskomoroch on x
    This is one hell of a “bug” for an email app: https://twitter.com/...
  • @cabel @cabel on x
    Remember this? All I wanted was a modern email client that downloaded directly from the server — like they have forever — with no risky middleman. The Edison privacy policy said “we store as little of your email on our servers as possible”. Well, sadly, https://www.macrumors.com/…
  • @chancehmiller Chance Miller on x
    One of the many reasons I will never use a third-party email app. https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    “At this time this appears to be a bug and not a security breach.” — Edison I get the desire to spin, but this is just wordplay bullshit. Edison should probably revisit its definition of what a breach is. Allowing unauthorized access to other people's email accounts is a breach. …