While the video demonstrates the flaw by launching some pretty low-key apps, maliciously-coded emails could cause your phone to compromise some very important personal data. There doesn't seem to be a fix for the issue just yet, so if you're using Mailbox on your iOS device, it's probably a good idea to switch to another email app until this problem is sorted.

Advertisement
Advertisement

Update: Here's Mailbox's statement on this issue.

Many thanks to the community for continuing to push Mailbox to be as great an app as possible. As others have noted, the risks here are extremely limited thanks to the inter-app security built into iOS. That being said, we're working on an improvement to mail formatting that will mitigate the issue entirely and aim to ship it soon.

2nd Update: on its blog, Mailbox says the problem is now fixed:

[T]oday we implemented a process that strips JavaScript from messages before delivering them to mobile devices. This feature is now live on Mailbox servers and filtering new mail.

Advertisement

[Michele Spagnuolo via Ars Technica]