[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

iOS 8.1.2 Mail.app Injection - Load remote content without user interaction

[ 0Day-ID-23128 ]
Full title
iOS 8.1.2 Mail.app Injection - Load remote content without user interaction [ Highlight ]
Highlight - is paid service, that can help to get more visitors to your material.

Price: 10
Date add
Category
Platform
Verified
Price
 
0.002 BTC

 
150 USD
Risk
[
Security Risk High
]
Rel. releases
Description
This exploit allows an attacker to load remote website inside iOS's native Mail.app without any user interaction other than opening the HTML e-mail message containing the payload.


Example:
After opening the malicious message: http://i.imgur.com/GPMqdOv.jpg (iPhone) http://i.imgur.com/zJ7W24N.jpg (iPad)
The e-mail body is instantly (the delay is configurable) replaced by the attacker's website: http://i.imgur.com/LJSyV4F.jpg (iPhone) http://i.imgur.com/SlhkTzR.jpg (iPad)
Vendor
http://apple.com
Affected ver
all versions (<=8.1.2)
Tested on
iPhone, iPad
Solution
currently no solution
Tags
ios   html   injection  
Other Information
Abuses
0
Comments
0
Views
8 349
We DO NOT use Telegram or any messengers / social networks! We DO NOT use Telegram or any messengers / social networks! Please, beware of scammers!
Please login or register to buy exploit.
OR
Buy incognito
0
0
Verified by 0day Admin
Verified by 0day Admin
This material is checked by Administration and absolutely workable.
Learn more about    GOLD:
0day.today Gold is the currency of 0day.today project and is denoted on this site as such image: . It used for paying for the services, buying exploits, earning money, etc
We accept:
BitCoin (BTC)
You can pay us via BTC
LiteCoin (LTC)
You can pay us via LTC
Ethereum (ETH)
You can pay us via ETH

Author
BL
29
Exploits
1
Readers
0
[ Comments: 0 ]
Terms of use of comments:
  • Users are forbidden to exchange personal contact details
  • Haggle on other sites\projects is forbidden
  • Reselling is forbidden
Punishment: permanent block of user account with all Gold.

Login or register to leave comments