watchOS 8.5 Fixes Mail Privacy Protection Loophole That Could Expose IP Addresses

This article has been indexed from MacRumors: Mac News and Rumors – Front Page

watchOS 8.5 fixes a security vulnerability in the Mail app that could leak a user’s IP address when downloading remote content, security researchers have found.



Last year, it emerged that Apple’s Mail Privacy Protection feature was undermined by a lack of Apple Watch support. Mail Privacy Protection was a new feature introduced with iOS 15, iPadOS 15, and macOS Monterey that hides your IP address so senders are not able to determine your location or link email habits to your other online activity. It also prevents senders from tracking whether you opened an email, how many times you viewed an email, and whether you forwarded the email.

The feature works by routing all content downloaded by the Mail app through multiple proxy servers to strip your IP address, and then it assigns a random IP address that corresponds to your general region, making email senders see generic information rather than specific information about you.

Apple’s legal documentation on Mail Privacy Protection indicates that the feature is available for iPhone, iPad, and Mac only, but security researchers and developers Talal Haj Bakry and Tommy Mysk discovered that since the Apple Watch does not hide a recipient’s IP address, it can compromise the overall security provided by Mail Privacy Protection.

The Apple Watch downloads remote content, such as images, using the recipient’s real IP address, both when receiving a Mail notifi

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

Read the original article: watchOS 8.5 Fixes Mail Privacy Protection Loophole That Could Expose IP Addresses