(Original title: Two Apple Mail vulnerabilities being used to target iPhone, iPad users)
NetEase Tech, April 23 — According to foreign media, researchers at the US cybersecurity firm ZecOps announced Wednesday that they found two zero-day vulnerabilities in Apple’s iPhone and iPad Mail apps.
Researchers say variants of these two vulnerabilities can be traced back to iOS 6 released in 2012, meaning hackers have used them to attack iPhone and iPad users for eight years. If a device is infected, the user may not even know they’re being hacked.
The first vulnerability allows hackers to infect an iOS device by sending an email that consumes a lot of memory. By itself it doesn’t pose much risk to the user — it only lets the attacker leak, modify, or delete emails. But it works even on the latest version of iOS, and the hacker can use anything the Mail app can access, including confidential messages.
The second vulnerability exploits Apple’s MobileMail and Mailid processes to run remote code. Combined with another kernel attack (like the unpatchable Checkm8 vulnerability), this vulnerability could allow the attacker to access a specific target device as a superuser.
ZecOps found in its report that some customers had already been targeted. Interestingly, although there is evidence these vulnerabilities were executed on target devices, the emails themselves were not dangerous. This suggests the attackers deleted these emails to cover their tracks.
Security researchers said that, compared with other hackers, this vulnerability is relatively unrefined, meaning experienced attackers might consider using it against important targets too risky.
Nevertheless, ZecOps noted that attacks using these vulnerabilities may increase, because they are now publicly disclosed, meaning ordinary users may eventually become targets too. If cybercriminals exploiting these vulnerabilities can leverage additional vulnerabilities, the situation becomes more dangerous.
These vulnerabilities only affect the native Mail app, not third-party apps. To reduce the risk of attack, ZecOps advised users to stop using Mail on iOS and iPadOS before a patch is released, and switch to third-party email apps.
ZecOps said it alerted Apple to these vulnerabilities in February. Since then, both vulnerabilities have been fixed in the latest beta of iOS 13, and the patch will also be added in the next public iOS update, iOS and iPadOS 13.4.5. (Xiaoxiao)
