watchOS 8.5 Fixes Mail Privacy Protection Loophole That Could Expose IP Addresses

watchOS 8.5 fixes a security vulnerability in the Mail app that could leak a user's IP address when downloading remote content, security researchers have found.

ios15 mail privacy feature
Last year, it emerged that Apple's Mail Privacy Protection feature was undermined by a lack of Apple Watch support. Mail Privacy Protection was a new feature introduced with iOS 15, iPadOS 15, and macOS Monterey that hides your IP address so senders are not able to determine your location or link email habits to your other online activity. It also prevents senders from tracking whether you opened an email, how many times you viewed an email, and whether you forwarded the email.

The feature works by routing all content downloaded by the Mail app through multiple proxy servers to strip your IP address, and then it assigns a random IP address that corresponds to your general region, making email senders see generic information rather than specific information about you.

Apple's legal documentation on Mail Privacy Protection indicates that the feature is available for iPhone, iPad, and Mac only, but security researchers and developers Talal Haj Bakry and Tommy Mysk discovered that since the Apple Watch does not hide a recipient's IP address, it can compromise the overall security provided by Mail Privacy Protection.

The Apple Watch downloads remote content, such as images, using the recipient's real IP address, both when receiving a Mail notification and when opening an email, meaning that even for users who had enabled Mail Privacy Protection on their ‌iPhone‌, their IP address can be exposed.

While Mail Privacy Protection is a feature exclusive to iOS 15, ‌iPadOS 15‌, and ‌macOS Monterey‌, the fact that simply receiving a Mail notification on the Apple Watch could reveal a user's IP address and bypass Mail Privacy Protection on other devices seemed to be an oversight. Now, Bakry and Mysk have found that Apple has fixed the issue in watchOS 8.5.

As of watchOS 8.5, loading remote content is automatically blocked on the Apple Watch, and instead provides an option to "Load Content Directly." Users can also select "Always Load Content Directly" for all new emails or "Ask to Load Content" on a per-email basis. The improvement was not included in watchOS 8.5's release notes.

watchOS 8.5 was released to the public yesterday and the update brings a number of other improvements, including updates to irregular heart rhythm notifications designed to improve atrial fibrillation identification, audio hints in Apple Fitness+ workouts, the ability to authorize Apple TV purchases and subscriptions, and the ability to restore an Apple Watch using an iPhone.

Top Rated Comments

msackey Avatar
10 months ago

The watchOS team really needs a shake-down. I’ve got the newest watch, and it has recently been the glitchiest of all my Apple devices.
Shortcuts on Apple Watch are very glitchy too.

Anytime you have a Prompt with text in which the input is numeric (e.g., “Please input your weight” and the input is numbers only), the Apple Watch will not display the prompt and only ask you to input numbers. When you have a Shortcut with various prompts (e.g., What is your weight? What is your BMI? etc.) you need to see what the prompt is asking otherwise you lose your place and don’t know what the context is for inputting numbers! This doesn’t even need explanining.

This issue has been with us since about the last two Apple WatchOS versions!
Score: 3 Votes (Like | Disagree)
twistedpixel8 Avatar
10 months ago

Security vulnerability is a part of life.

It will always happen.
True, but this one was ridiculous for Apple to miss.
Score: 3 Votes (Like | Disagree)
pdaholic Avatar
10 months ago
The watchOS team really needs a shake-down. I’ve got the newest watch, and it has recently been the glitchiest of all my Apple devices.
Score: 3 Votes (Like | Disagree)
dk001 Avatar
10 months ago
Things like this make you wonder how segregated Apple teams are.
This should not have been missed.
Score: 2 Votes (Like | Disagree)
twistedpixel8 Avatar
10 months ago

The two most egregious glitches for me are the random failure to charge (even with the oem charger) and my inability to turn off screen time downtime. Downtime randomly turns on and I have to reboot the watch to get it to turn off, otherwise the watch is useless. There are other glitches, but those stand out!
I was almost late for work this morning because haptics just completely stopped and my watch alarm is set to vibrate only.
Score: 2 Votes (Like | Disagree)
pdaholic Avatar
10 months ago

Shortcuts on Apple Watch are very glitchy too.

Anytime you have a Prompt with text in which the input is numeric (e.g., “Please input your weight” and the input is numbers only), the Apple Watch will not display the prompt and only ask you to input numbers. When you have a Shortcut with various prompts (e.g., What is your weight? What is your BMI? etc.) you need to see what the prompt is asking otherwise you lose your place and don’t know what the context is for inputting numbers! This doesn’t even need explanining.

This issue has been with us since about the last two Apple WatchOS versions!
The two most egregious glitches for me are the random failure to charge (even with the oem charger) and my inability to turn off screen time downtime. Downtime randomly turns on and I have to reboot the watch to get it to turn off, otherwise the watch is useless. There are other glitches, but those stand out!
Score: 1 Votes (Like | Disagree)

Related Stories

General iOS 15

Apple Seeds Fourth Betas of iOS 15.2 and iPadOS 15.2 to Developers [Update: Public Beta Available]

Thursday December 2, 2021 10:07 am PST by
Apple today seeded the fourth betas of upcoming iOS and iPadOS 15.2 updates to developers for testing purposes, two weeks after seeding the third betas and a month after the launch of iOS 15.1 and iPadOS 15.1. iOS and iPadOS 15.2 can be downloaded through the Apple Developer Center or over the air after the proper profile has been installed on an iPhone or an iPad. iOS and iPadOS 15.2 add ...
icloud mail redesign

Web-Based iCloud Mail Redesign, Hide My Email, and Custom Domain Features Now Live

Monday September 20, 2021 1:00 pm PDT by
Alongside the launch of iOS 15, iPadOS 15, tvOS 15, and watchOS 8, Apple has also pushed an update for its iCloud.com website, introducing a new look for iCloud Mail that's viewed on the web. The new web-based iCloud Mail design looks similar to the Mail apps on devices running iOS 15, iPadOS 15, and the beta version of macOS Monterey. It is a cleaner and more streamlined look than the prior ...
watchOS 8 on Apple Watch feature

Apple Releases watchOS 8.5 With Support for Apple TV Purchase Authorization, Irregular Heart Rhythm Notification Improvements and More

Monday March 14, 2022 9:42 am PDT by
Apple today released watchOS 8.5, the fourth major update to the watchOS 8 operating system that launched in September. watchOS 8.5 comes two months after the launch of watchOS 8.4, which fixed a charging bug. ‌‌watchOS ‌8.5 can be downloaded for free through the dedicated Apple Watch app on the iPhone by going to General > Software Update. To install the new software, the Apple Watch needs...
Edison Mail M1 Mac Support

Edison Mail Updated With Native Support for Apple Silicon Macs

Thursday February 17, 2022 8:02 am PST by
Edison Mail today announced that it has updated its Mac app with native support for Apple silicon, allowing the app to run faster on Macs powered by the M1, M1 Pro, and M1 Max chips. The new version of the app is available now through the Mac App Store. Edison Mail first released a desktop app for the Mac in 2019 with features such as One-Click Unsubscribe for junk emails, Block Sender,...
watchOS 8 on Apple Watch feature

Apple Seeds watchOS 8.4 Release Candidate to Developers

Thursday January 20, 2022 10:10 am PST by
Apple today seeded the release candidate version of an upcoming watchOS 8.4 beta to developers for testing purposes, with the new software coming one week after the launch of the first betas and over a month after the release of watchOS 8.3. To install watchOS 8.4, developers will need to download the configuration profile from the Apple Developer Center. Once installed, ‌‌‌‌watchOS...
watchOS 8 on Apple Watch feature

Apple Releases watchOS 8.4 With Fix for Apple Watch Charging Bug

Wednesday January 26, 2022 9:50 am PST by
Apple today released watchOS 8.4, the third major update to the watchOS 8 operating system that launched in September. watchOS 8.4 comes over a month after the release of watchOS 8.3, an update that added support for the Apple Music Voice Plan. ‌‌watchOS ‌8.4 can be downloaded for free through the dedicated Apple Watch app on the iPhone by going to General > Software Update. To install the...
custom email domain mail ios 15 4

iOS 15.4 Beta Adds Support for Setting Up Custom Email Domains With iCloud Mail

Thursday January 27, 2022 5:25 pm PST by
The iOS 15.4 beta that was introduced today expands support for the custom email domain feature available for iCloud+, adding an option to set up a custom domain with iCloud Mail directly on the iPhone. If you go to Settings > Apple ID > iCloud, "iCloud Mail" is now a tappable option and it includes a section for setting up a Custom Email Domain. Prior to now, custom domains were able to...
ios15 mail privacy feature

Hide My Email Available in Mail App With New iOS 15.2 and macOS Monterey 12.1 Betas

Tuesday November 9, 2021 10:42 am PST by
iCloud+ subscribers who use Hide My Email can do so directly from the Mail app after installing the iOS 15.2, iPadOS 15.2, and macOS Monterey 12.1 betas that came out today. The feature update is outlined in Apple's release notes for the beta, and it should make Hide My Email much more convenient to use on Apple devices. For those unfamiliar with Hide My Email, it is an iOS 15 and macOS...

Popular Stories

Apple advanced security Advanced Data Protection screen Feature

FBI Calls End-to-End Encryption 'Deeply Concerning' as Privacy Groups Hail Apple's Advanced Data Protection as a Victory for Users

Thursday December 8, 2022 2:45 am PST by
Apple yesterday announced that end-to-end encryption is coming to even more sensitive types of iCloud data, including device backups, messages, photos, and more, meeting the longstanding demand of both users and privacy groups who have rallied for the company to take the significant step forward in user privacy. iCloud end-to-end encryption, or what Apple calls "Advanced Data Protection,"...
General iOS 16 Feature Yellow

iOS 16.2 for iPhone Expected to Launch Next Week With These 12 New Features

Thursday December 8, 2022 7:05 am PST by
iOS 16.2 is expected to be released next week following nearly two months of beta testing. With last-minute additions like Apple Music Sing and Advanced Data Protection, the software update now has over a dozen new features for the iPhone. Below, we've recapped many of the new features coming with iOS 16.2, including Apple's new whiteboard app Freeform, two new Lock Screen widgets, the...
maxresdefault

Can't Get an iPhone 14 Pro? Here's Why You Should Wait for the iPhone 15 Ultra

Monday December 5, 2022 11:44 am PST by
Due to production issues at Apple supplier factories in China, the iPhone 14 Pro and iPhone 14 Pro Max are backordered and basically out of stock at every store. If you were planning to gift or receive an iPhone 14 Pro model for the holidays and didn't already get one, you're basically out of luck because they're gone until late December. Subscribe to the MacRumors YouTube channel for more ...
maxresdefault

Hands-On With Apple Music Sing in iOS 16.2

Wednesday December 7, 2022 12:24 pm PST by
With the iOS 16.2 release candidate that came out today, Apple added the new Apple Music Sing feature that was announced earlier this week. We thought we'd check out the new karaoke feature to see how it works. Subscribe to the MacRumors YouTube channel for more videos. Apple Music Sing is available on modern iPhones and iPads, as well as the newest Apple TV 4K. It's built in to the Apple...
General iOS 16 Feature Yellow

iOS 16.2 for iPhone Launching This Month With These 8 New Features

Thursday December 1, 2022 8:44 am PST by
Apple plans to publicly release iOS 16.2 for the iPhone in mid-December, according to Bloomberg's Mark Gurman. The update remains in beta testing for now, with at least eight new features and changes already uncovered so far. iOS 16.2 introduces a number of new features, including Apple's new whiteboard app Freeform, two new Lock Screen widgets for Sleep and Medications, the ability to hide...
Apple Accessories Deals 2022 Anker

Deals: Amazon's New Anker Sale Has Savings on USB-C Chargers, Portable Batteries, and More

Wednesday December 7, 2022 8:10 am PST by
Anker this week has introduced a new sale across its most popular accessories on Amazon, including savings on USB-C cables, wall chargers, portable batteries, wireless chargers, and more. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. Many of these sales...
Apple advanced security Advanced Data Protection screen Feature

Apple Announces End-to-End Encryption Option for iCloud Photos, Notes, Backups, and More

Wednesday December 7, 2022 10:00 am PST by
Apple today announced it is expanding end-to-end encryption to many additional iCloud data categories on an opt-in basis for enhanced security. iCloud already protects 14 data categories using end-to-end encryption by default, including the Messages app when backups are disabled, passwords stored in iCloud Keychain, Health data, Apple Maps search history, Apple Card transactions, and more,...
Twitter Feature

Twitter to Charge $11 Per Month for Twitter Blue on iPhone, $7 on Website

Wednesday December 7, 2022 6:47 pm PST by
Twitter plans to charge $11 per month for a Twitter Blue subscription on the iPhone in order to account for the 30 percent cut that Apple takes from in-app purchases, reports The Information. On the web, Twitter Blue will be priced at $7 per month. Prior to when Twitter Blue was paused, Twitter was charging $7.99 for a subscription, but the pricing will change before it relaunches. According ...
Apple car wheel icon feature yellow

Apple to Charge Under $100,000 for Apple Car, Launch Planned for 2026

Tuesday December 6, 2022 2:31 pm PST by
Apple is aiming to launch an Apple-branded consumer-oriented vehicle by 2026, and its goal is to hit a price point under $100,000 to make the car appeal to a wider range of customers, reports Bloomberg. Apple initially planned to design a car that might look similar to Canoo's Lifestyle Vehicle, where passengers could face one another in a limousine-style car with no steering wheel or...