Live data from Hacker News

Zero click vulnerability in Apple’s macOS Mail

mikko-kenttala.medium.com

11–20 of 269 posts

Re: Zero click vulnerability in Apple’s macOS Mail

#11
post #3

That's gonna be devastating to the three people who use Mail.app

With the Mail.app pegging their CPU to 100%, those three people are unlikely to notice. Frankly, it's unlikely for the attacker to be able to do anything either, aside from force-terminating Mail.app. (Disclaimer: I want to like Mail.app, but I don't need another fan in my office.)

[deleted]

Re: Zero click vulnerability in Apple’s macOS Mail

#12
post #3

That's gonna be devastating to the three people who use Mail.app

With the Mail.app pegging their CPU to 100%, those three people are unlikely to notice. Frankly, it's unlikely for the attacker to be able to do anything either, aside from force-terminating Mail.app. (Disclaimer: I want to like Mail.app, but I don't need another fan in my office.)

I'm using Mail.app since 2007 when i switched to Mac and never had issues other than a couple of times around 2009-10 when it had sync problems with Gmail. ¯\_(ツ)_/¯

Re: Zero click vulnerability in Apple’s macOS Mail

#13
post #3

That's gonna be devastating to the three people who use Mail.app

With the Mail.app pegging their CPU to 100%, those three people are unlikely to notice. Frankly, it's unlikely for the attacker to be able to do anything either, aside from force-terminating Mail.app. (Disclaimer: I want to like Mail.app, but I don't need another fan in my office.)

The post indicated that the attacker can change the configuration, filters, as well as forwarding rules (exfil), this doesn’t seem terribly benign.

Re: Zero click vulnerability in Apple’s macOS Mail

#14
post #4

> 2020–05–16: Issue found > 2020–05–24: PoC done and reported to Apple > 2020–06–04: Catalina 10.15.6 Beta 4 with [hotfix released] > 2020–07–15: Catalina 10.15.6 Update with hotfix released

> 2021–03–30: Bug Bounty is still being evaluated

If Apple are actually serious, why are they taking so long to give the bounty? It's sounds like madness to me.

Re: Zero click vulnerability in Apple’s macOS Mail

#15
post #9
post #3

That's gonna be devastating to the three people who use Mail.app

It’s my main email client, what’s wrong with it?

What’s right with it? I tried it a few times and always returned to web-based clients (on desktop) and third-party apps (outlook, gmail, protonmail) on iOS.

Re: Zero click vulnerability in Apple’s macOS Mail

#16
post #6
post #3

That's gonna be devastating to the three people who use Mail.app

That's not what the statistics say: https://emailclientmarketshare.com

Wow, Mail.app has more market share than Outlook. I'm pleasantly surprised. Ditto for GMail only having ~30%.

Although,

> Since determining the client in which an email is opened requires images to be displayed, the data for some email clients and mobile devices might be over- or under-represented due to automatic image blocking.

Outlook doesn't display external images by default, while Mail.app does, so....

Post reply on HN