Image via hilalabdullah / Shutterstock.com
Apple has dismissed newly-discovered security vulnerabilities in its default Mail app for the iPhone and iPad, describing that the attempted exploitations are “insufficient” in getting through its security system.
The investigation was made by cybersecurity firm ZecOps, who in a blog post
detailed that it had “high confidence” the attack had been “widely exploited in the wild in targeted attacks by an advanced threat operator(s).”
ZecOps said six high-profile characters from around the world were also targeted, including “individuals from a Fortune 500 organization in North America” and “an executive from a carrier in Japan.”
Hackers would send out seemingly blank emails to iPhone or iPad users. Recipients who open the messages would trigger a malicious code made to crash the Mail app, and while the app is rebooted, cyber-attackers would purportedly be able to access information stored in the device without the person’s knowledge.
What makes this supposed vulnerability particularly alarming is that recipients need not do anything other than open the email in order for hackers to attempt an infiltration. There is no need to download a file or visit a malware-infested link.
The firm was unable to obtain or study the code delivered to users, because the hackers were able to delete the email messages themselves.
ZecOps believes that the vulnerability has been around since iOS 6. Apple had not been aware of the flaw until March, when the cybersecurity firm reported it.
The findings have sent users on high alert since this attack could implicate hundreds of millions of users worldwide if successful.
However, the Cupertino giant has disproved concerns of the hack being dangerous enough to exploit users. “We have thoroughly investigated the researcher’s report and, based on the information provided, have concluded these issues do not pose an immediate risk to our users,” an Apple representative responded.
“The researcher identified three issues in Mail, but alone they are insufficient to bypass iPhone and iPad security protections, and we have found no evidence they were used against customers.”
According to ZecOps, Apple has patched the vulnerability in the latest iOS beta release. Apple users will be able to update to the public version in the coming weeks.
[via
Bloomberg, cover image via
hilalabdullah / Shutterstock.com]