Apple
Apple Mail: vulnerabilities and CVEs
Apple Mail has 7 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months1
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56547 | Low (3.5) | 0.28% | — | Aug 26, 2026 | The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them. The values cannot be changed later… |
| CVE-2017-17689 | Medium (5.9) | 4.1% | — | May 16, 2018 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. |
| CVE-2017-17688 | Medium (5.9) | 5.5% | — | May 16, 2018 | The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications… |
| CVE-2010-3887 | Medium (4.3) | 1.2% | — | Oct 8, 2010 | The Limit Mail feature in the Parental Controls functionality in Mail on Apple Mac OS X does not properly enforce the correspondence whitelist, which allows remote attackers to bypass intended access restrictions and… |
| CVE-2008-4491 | Medium (5) | 1.2% | — | Oct 8, 2008 | Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email server, which allows server owners and remote man-in-the-middle… |
| CVE-2008-0039 | Medium (6.8) | 3.2% | — | Feb 12, 2008 | Unspecified vulnerability in Mail in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary commands via a crafted file:// URL. |
| CVE-2005-2512 | Low (2.1) | 0.37% | — | Aug 19, 2005 | Mail.app in Mac OS 10.4.2 and earlier, when printing or forwarding an HTML message, loads remote images even when the user's preferences state otherwise, which could result in a privacy leak. |