Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster
Apr 12, 2001
67,805
38,412


Several users of popular email app Edison Mail this morning are reporting that they are able to see email accounts of other users within the iOS app. In what appears to be a major privacy breach, users report that after enabling a new sync feature, they have full access to these other email accounts.

edison_mail_devices.jpg

The new sync feature was recently rolled out by Edison to allow connected email accounts to show up across all of your devices, but clearly something has gone significantly wrong with the feature.



Users have also reported being able to see that other devices are linked to their accounts, indicating that others are able to see their emails.


Edison has yet to reply to any of the tweets from users reporting the issue, but at this time it certainly seems advisable for Edison Mail users who have enabled the sync feature to delete their email accounts from the app.

While it's unlikely that users would be able to directly see the passwords of others' email accounts, affected users may still want to change the passwords on their email accounts for some added peace of mind until more details on exactly what the issue is surface.

Update 8:35 a.m.: Edison has started replying to users on Twitter to say that the company is "urgently working to resolve this technical problem" and has reverted the change that introduced the problem for a "small percent of our users" yesterday.



(Thanks, Chris!)

Article Link: Edison Mail Sync Bug Allowing Access to Other Users' Email Accounts [Updated]
 
Last edited:
  • Angry
  • Like
Reactions: adib and agmmac
This is why I would never use a client that isn't from one of the big three (Apple/Microsoft/Google). Not worth little surprises like this.

My experiences:

Apple Mail = sometimes no notifications or new emails are not showing up

Outlook = iCloud Mail only works for a few days

Gmail = It’s great but sometimes not getting notifications either

Outlook is my favorite, but as long they don’t fix the problem I cannot use it. And Edison is the only one which works.
 
  • Disagree
Reactions: jezbd1997
This is definitely not good, That is exactly why you always use end-to-end encryption and transport the encryption key separately from the data itself.

And in the terms of password confirm the password on each device and do not transfer it in any way over the internet, without a second layer of encryption with a key the program does not know.
 
  • Like
Reactions: u+ive
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.