Apple says 'no evidence' iPhone mail flaw used against customers

Apple says 'no evidence' iPhone mail flaw used against customers
People wearing face masks in an Apple store in Hangzhou, Zhejiang province, China, on April 24, 2020.
PHOTO: Reuters

WASHINGTON - Apple Inc said on Thursday (April 23) it has found "no evidence" a flaw in its e-mail app for iPhones and iPads has been used against customers, and that it believes the flaw does "not pose an immediate risk to our users".

San Francisco-based security firm ZecOps on Wednesday detailed a flaw that it said may have left more than half a billion iPhones vulnerable to hackers.

Mr Zuk Avraham, ZecOps' chief executive, told Reuters he found evidence the vulnerability was exploited in at least six cybersecurity break-ins.

Mr Avraham said he found evidence that an attacker was taking advantage of the vulnerability as far back as January 2018, but that he could not determine who the hackers were.

Reuters was unable to independently verify his claim.

Apple on Wednesday acknowledged the vulnerability existed in its software for e-mail on iPhones and iPads, known as the Mail app, and said the company had developed a fix that will be introduced in a forthcoming update to millions of devices it has sold globally.

On Thursday, Apple disputed Mr Avraham's evidence that the hack had been used against iPhone users.

"We have thoroughly investigated the researcher's report and, based on the information provided, have concluded these issues do not pose an immediate risk to our users," Apple said in a statement.

"The researcher identified three issues in Mail, but alone they are insufficient to bypass iPhone and iPad security protections, and we have found no evidence they were used against customers."

Mr Avraham did not immediately respond to a request for comment on Apple's statement.

This website is best viewed using the latest versions of web browsers.