The security breach apparently affects iPhone Mail and Safari running on firmware 1.1.4 and 2.0. However, earlier versions may also be vulnerable.
To avoid being spoofed, Raff recommends that users manually input URLs into iPhone's Safari browser and avoid clicking on Mail links until Apple releases a fix.
Apple has acknowledged the gaping hole in its iPhone Mail application and launched an investigation into Safari's alleged vulnerability to forged URLs. ยต
iPhone vulnerable to hack attacks
Insecurity researcher Aviv Raff has warned that iPhone's Mail and Safari applications are prone to a URL spoofing vulnerability that could direct unsuspecting surfers to malicious phishing sites.
Got a news tip for our journalists? Share it with us anonymously here.
SPONSORED RESOURCES
Secure your AI future with generative AI defense
See how F5 protects modern applications against evolving threats
Accelerate AI adoption with a cloud-first strategy
Frontier AI has changed the security landscape. Is your defence ready?
F5 sets the standard for cloud application security
HPE Networking Day Sydney
iTnews Resilience, Rewired Breakfast
RIMPA Live Convention 2026
What’s Next?
iTnews Benchmark Security Awards 2026



