Users of iOS, beware. An unfixed vulnerability has been found in the Mail app, which allows hackers to steal passwords by sending an email. The flaw was first noticed by Ernst and Young forensic bod Jan Soucek. He has created
a tool capable of generating slick iCloud password phishing emails he says exploits an unpatched bug. He has even recorded a proof-of-concept video. He made an iOS 8.3 Mail.app inject kit. It exploits a bug in the native email app and can produce a realistic pop-up. Soucek explained that he first told Apple about the bug in January, but that the company had not responded or fixed the problem. Now he has opted for a more extreme approach. The complete kit is available on
Github.