Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Serious Flaw in iOS Mail App Exposes Users to Phishing Attacks

The email client shipped with Apple’s iOS mobile operating system is plagued by a vulnerability that can be exploited to load remote arbitrary HTML content in the application, a researcher has warned.

The email client shipped with Apple’s iOS mobile operating system is plagued by a vulnerability that can be exploited to load remote arbitrary HTML content in the application, a researcher has warned.

Czech researcher Jan Souček published proof-of-concept (PoC) code and a video earlier this week to demonstrate his findings.

The expert discovered in January that the iOS email client (Mail.app) doesn’t ignore the <meta http-equiv=refresh> HTML tag in email messages. This allows an attacker to create emails that load remote HTML content when opened.

“JavaScript is disabled in this UIWebView, but it is still possible to build a functional password ‘collector’ using simple HTML and CSS,” Soucek said.

The researcher has published a video in which he shows how an attacker can send out a specially crafted email that prompts recipients to enter their iCloud credentials. The username and password collected from the victim are then sent back to the attacker.

Users noted on Hacker News that such an attack is likely to work against many internauts because it’s not uncommon for them to be asked to enter their iCloud credentials and the genuine dialog box designed by Apple is easy to replicate.

Souček has published the source code for an iOS 8.3 “inject kit” on GitHub. The expert has pointed out that this is just an example to demonstrate the existence of the vulnerability, which can be leveraged for other attacks as well, not just credentials harvesting.

“The vulnerability can be used for anything that requires HTML tags not supported by Mail.app,” Souček explained.

Advertisement. Scroll to continue reading.

The researcher said he reported the flaw to Apple back in January via the company’s Radar bug tracking system. He has now decided to publicly disclose the vulnerability because Apple has failed to take any action.

It’s worth noting that Apple released the first iOS 9 Beta and iOS 8.4 Beta 4 this week, but it’s unclear if these versions address the vulnerability. Even if they do fix the flaw, these variants are currently only available to developers.

Independent security analyst Graham Cluley has pointed out that the code published by the researcher might be put to good use by malicious hackers and identity thieves.

“Although I can understand his frustration with Apple’s lack of response for fixing the issue, Soucek could have applied pressure to the company by demonstrating the flaw to the tech media, rather than releasing exploit code for potential misuse,” Cluley wrote in a blog post for Tripwire. “Meanwhile, as we wait for Cupertino to roll out a patch, it would be wisest to either exercise extreme caution whenever an unexpected pop-up appears while perusing our Mail inbox, or use a third-party email app instead.”

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.