Beware authentication popups in iOS Mail: bug allows convincing-looking phishing attacks
[youtube=https://www.youtube.com/watch?v=9wiMG-oqKf0]
Update: Apple confirmed it’s aware of the issue and working on a fix:
“We are not aware of any customers affected by this proof of concept, but are working on a fix for an upcoming software update.”
If you are reading mail on your iPhone and iPad and a popup appears asking you to re-login to iCloud (or anything else), beware. Security researcher Jan Soucek discovered a bug in the iOS Mail app that allowed an attacker to run remote HTML code when an email is opened. That code could easily imitate an iCloud login prompt, fooling users into giving away their Apple ID credentials …
Expand
Expanding
Close
