iPhone OS 3.0 Mail security issue fixed in OS 3.1
A video posted recently on YouTube demonstrates, on an iPod Touch, a potential security risk for users of iPhone OS 3.0. The bug allows e-mails that have already deleted to be viewed by searching for the title of the deleted message.
The results of the search display two copies of the message. Selecting either one of these the first time will cause Mail to crash. The second time you select the messages, the iPhone may display the original message or you may get a warning that states: “Message cannot be displayed because of the way it is formatted.” You should note that the message is displayed in Mail as “1 of 0″ and it is “partially downloaded.” The download button used to retrieve the remainder of the message doesn’t work.
<!–
If you consider that you have to know the title in order to find what you are looking <!– for is this really a big problem? After all it would be hard to guess some titles outright, <!– but any thief spending enough time with your iPhone or iPod could see results from one <!– or more lucky guesses.
Fortunately, one developer said this problem appears to have been resolved in iPhone OS 3.1 beta 3, since the developer was not able to recreate the bug after upgrading.
Related posts: