Executive brief
A privacy vulnerability in Apple's Mail application could allow remote images to be displayed even when Lockdown Mode is enabled. Lockdown Mode is a high-security setting designed to protect users against sophisticated cyberattacks by strictly limiting certain features. If exploited, this flaw could allow an attacker to track when a user opens or replies to an email, potentially exposing the user's IP address or location.
Technical details
A logic issue existed in the Mail Drafts component of Apple operating systems. The vulnerability was rooted in insufficient checks during the email reply process, which failed to maintain Lockdown Mode restrictions. An attacker could send a crafted email that, upon being replied to by the victim, would trigger the loading of remote content (images). This bypasses the privacy protections of Lockdown Mode, which is intended to block remote web content to prevent tracking and exploitation. The issue was addressed with improved logic and state checks in iOS 18.7.9, iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.
Affected products
- Apple iOS Before 18.7.9
- Apple iPadOS Before 18.7.9
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory