Skip to main content

Massive iPhone security flaw left millions of phones vulnerable to hacks

Over half a billion iPhones are vulnerable to hackers, and iPads are susceptible, too — and Apple is still working to deploy its fix.

Recommended Videos

The issue — which was discovered by cybersecurity company ZecOps exec Zuk Avraham — lies with Apple’s Mail app, which leaves devices vulnerable to hackers, according to Reuters.

Please enable Javascript to view this content

Avraham found a malicious program was exploiting the bug as far back as January 2018, though he’s not sure who was behind the program. He said iPhone owners who were affected were sent a blank email message that crashed the app and forced a reset.

Owners didn’t even have to open the message for the crash to happen, according to The Wall Street Journal. The Mail app downloading it was enough. Hackers could then access the device’s photos, contact, and other data. The vulnerability also left the Mail app susceptible to hackers, including the ability to see private messages.

Avraham doesn’t believe many people have been targeted by the malicious program. Apple said it’s fixed the issue, but it hasn’t yet widely deployed the patch via an update yet.

“Apple takes all reports of security threats seriously,” an Apple spokesperson said in an email Friday to Digital Trends. “We have thoroughly investigated the researcher’s report and, based on the information provided, have concluded these issues do not pose an immediate risk to our users. The researcher identified three issues in Mail, but alone they are insufficient to bypass iPhone and iPad security protections, and we have found no evidence they were used against customers. These potential issues will be addressed in a software update soon. We value our collaboration with security researchers to help keep our users safe and will be crediting the researcher for their assistance.”

Though Apple often touts the security of its products, this isn’t the first vulnerability researchers have found this year. In February, software developers found a flaw in Apple iOS’s copy-and-paste system. It affected both iPhones and iPads.

If you hit copy on some text on your device, it would assume you wanted to paste it into the next app you open. But if you accidentally hit copy and opened a different app, it would still be able to access whatever you copied. Essentially, any app or widget would be able to “see” whatever you had copied, if you opened it right after.

Tommy Mysk, one of the developers who found the problem, told Digital Trends that you can help combat the issue by disabling Universal Clipboard on your device.

If you’re wary about having the Mail app on your iPhone or iPad while waiting for Apple to deploy an update for the issue, you can always delete it.

Patrick Wardle, a security researcher at Jamf Software LLC, told the Wall Street Journal that’s probably unnecessary, as the malicious program seems very limited in reach at this point.

Jenny McGrath
Former Digital Trends Contributor
Jenny McGrath is a senior writer at Digital Trends covering the intersection of tech and the arts and the environment. Before…
Some iPhone users report overheating when using Apple Intelligence
The Nomad Magnetic Leather Back on the iPhone 16 Pro Max

After a long wait, iOS 18.2 has finally rolled out to the public at large and unlocked more Apple Intelligence features like Image Playground, Genmoji, and an upgraded Mail app. It might have also introduced a way to keep your hands warm on these frosty winter days, according to some users.

Reddit user u/dsdxp posted on the iPhone subreddit that they had unlocked a secret feature in the iPhone 16 Pro. The comment was obviously sardonic, but many other users responded with their own stories of troubling temperatures from their iPhones. The common element between all of the stories was the Image Playground app and the excessive heat it creates while in use.

Read more
Apple is about to stop selling multiple iPhones in Europe. Here’s why
The iPhone 14 Plus held in a man's hand.

The iPhone SE and iPhone 14 series will no longer be available for purchase in Europe at the end of the year. In an effort to make technology more consumer-friendly, the European Union ruled that any mobile device sold must be able to charge through USB-C, according to iGeneration. While more modern entries in Apple's lineup already meet those guidelines, the iPhone SE and iPhone 14 do not.

These aren't the newest additions to Apple's lineup, but the iPhone SE and the iPhone 14 series are still sold in Europe. These will be pulled from shelves as the deadline approaches. Customers have plenty of options, but this decision will leave the European market without an iPhone SE option until the next model releases in 2025.

Read more
Apple’s mysterious iPhone 17 Air is one step closer to becoming a reality
A render of the iPhone Air.

For months, rumors have indicated that Apple plans to remove the iPhone Plus from the 2025 iPhone 17 lineup, and replace it with an entirely new model that might be called the “iPhone 17 Air.” A new report suggests that this phone is now closer to becoming a reality.

According to Digitimes, the new phone has entered the initial stage of manufacturing, known as the new product introduction (NPI) phase. At this stage, Apple and its manufacturing partners finalize a blueprint for creating the phone. It's a significant step in the process.

Read more