{"id":14655,"date":"2020-04-24T11:32:17","date_gmt":"2020-04-24T09:32:17","guid":{"rendered":"https:\/\/info.gwdg.de\/news\/en\/?p=14655"},"modified":"2020-04-24T12:04:49","modified_gmt":"2020-04-24T10:04:49","slug":"information-severe-security-vulnerability-in-apples-mail-app-on-ios-devices","status":"publish","type":"post","link":"https:\/\/info.gwdg.de\/news\/information-severe-security-vulnerability-in-apples-mail-app-on-ios-devices\/","title":{"rendered":"Information: severe security vulnerability in Apples Mail app on iOS devices"},"content":{"rendered":"<p><span style=\"text-decoration: underline;\"><strong>Message-Id:<\/strong><\/span> 202004231043<br \/>\n<span style=\"text-decoration: underline;\"><strong>Time:<\/strong><\/span> since Apr 23rd, 2020<br \/>\n<span style=\"text-decoration: underline;\"><strong>Affected:<\/strong><\/span> all iOS devices<br \/>\n<span style=\"text-decoration: underline;\"><strong>Impact:<\/strong><\/span> \u00a0An attacker gains access to the entire system via this new vulnerability<\/p>\n<p>Since Apr 23rd, 2020, the BSI has warned of a critical vulnerability in the Mail app of iOS<\/p>\n<p><a href=\"https:\/\/www.bsi.bund.de\/EN\/TheBSI\/thebsi_node.html\" class=\"external\" rel=\"nofollow\">https:\/\/www.bsi.bund.de\/EN\/TheBSI\/thebsi_node.html<\/a><\/p>\n<p>This potentially affects all iPhone and iPad devices that use the Apple Mail app. An attacker can use this new vulnerability to gain access to the entire system without users noticing anything.<\/p>\n<p>Up to now it is difficult to detect whether a device is already affected or not, only a clear &#8222;slow down&#8220; of the device can be a first indication.<\/p>\n<p>Until then, the following rules will help to protect yourself:<\/p>\n<p>Use Outlook Web Access (OWA) as an alternative mail access. To do this, open the Safari app on your iOS device and go to <a href=\"https:\/\/email.gwdg.de\" class=\"external\" rel=\"nofollow\">https:\/\/email.gwdg.de<\/a>. There, enter your own e-mail address (under domain\\username) and your password. Then you can tap on &#8222;Sign in&#8220;.<\/p>\n<p>Please deactivate email data synchronization on your iPhone and\/or iPad:<br \/>\nStep 1: Open &#8222;Passwords &amp; Accounts&#8220; in Settings.<br \/>\nStep 2: Change to &#8222;Data Synchronization&#8220;.<br \/>\nStep 3: Deactivate the PUSH function and set Retrieval to &#8222;Manual&#8220; for all accounts.<\/p>\n<p>After that, do not open the Apple Mail app any more, otherwise it will be retrieved manually and an attack would be successful again.<\/p>\n<p>Alternatively, you can disable email retrieval on your iOS devices completely. However, this will delete all your email on the iOS device in question.<\/p>\n<p>Apple has already announced a patch. Only then reset the changed settings on your iPhone \/ iPad to the normal operating mode.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Message-Id: 202004231043 Time: since Apr 23rd, 2020 Affected: all iOS devices Impact: \u00a0An attacker gains access to the entire system via this new vulnerability Since Apr 23rd, 2020, the BSI has warned of a critical vulnerability in the Mail app of iOS https:\/\/www.bsi.bund.de\/EN\/TheBSI\/thebsi_node.html This potentially affects all iPhone and iPad devices that use the Apple &#8230; <a title=\"Information: severe security vulnerability in Apples Mail app on iOS devices\" class=\"read-more\" href=\"https:\/\/info.gwdg.de\/news\/information-severe-security-vulnerability-in-apples-mail-app-on-ios-devices\/\" aria-label=\"Mehr Informationen \u00fcber Information: severe security vulnerability in Apples Mail app on iOS devices\">Weiterlesen<\/a><\/p>\n","protected":false},"author":132,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[43,8,9,10],"tags":[92,89,94,93,91,95],"class_list":["post-14655","post","type-post","status-publish","format-standard","hentry","category-email-en","category-mobile-en","category-operating-news","category-security","tag-app","tag-ios","tag-ipad","tag-iphone","tag-mail","tag-security-issue"],"_links":{"self":[{"href":"https:\/\/info.gwdg.de\/news\/wp-json\/wp\/v2\/posts\/14655","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/info.gwdg.de\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/info.gwdg.de\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/info.gwdg.de\/news\/wp-json\/wp\/v2\/users\/132"}],"replies":[{"embeddable":true,"href":"https:\/\/info.gwdg.de\/news\/wp-json\/wp\/v2\/comments?post=14655"}],"version-history":[{"count":6,"href":"https:\/\/info.gwdg.de\/news\/wp-json\/wp\/v2\/posts\/14655\/revisions"}],"predecessor-version":[{"id":14666,"href":"https:\/\/info.gwdg.de\/news\/wp-json\/wp\/v2\/posts\/14655\/revisions\/14666"}],"wp:attachment":[{"href":"https:\/\/info.gwdg.de\/news\/wp-json\/wp\/v2\/media?parent=14655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/info.gwdg.de\/news\/wp-json\/wp\/v2\/categories?post=14655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/info.gwdg.de\/news\/wp-json\/wp\/v2\/tags?post=14655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}