Security researchers said Monday they have discovered a critical flaw in the way certain email programs handle a popular encryption technology that safeguards emails from prying eyes.
The flaw, known as EFAIL, affects applications such as Mozilla Thunderbird, Apple Mail and some versions of Outlook, said the team of European researchers. EFAIL targets the encryption standard known as PGP, or Pretty Good Privacy, and S/MIME, a similar protocol commonly used by enterprises. (A full list of affected email programmess is available from the researchers' report).
Whistleblowers, political activists and others who depend on encrypted email could all be compromised by the bug, the researchers said in a blog post. The Electronic Frontier Foundation, a separate technology advocacy group that previewed the researchers' findings on Sunday, said users of the affected email programs should disable any third-party software they have installed that allow the email apps to use PGP or S/MIME. (EFF has provided step-by-step instructions for each type of mail client.)
"Until the flaws described in the paper are more widely understood and fixed," EFF said, "users should arrange for the use of alternative end-to-end secure channels, such as Signal, and temporarily stop sending and especially reading PGP-encrypted email."
The flaw works when an attacker already has access to a victim's encrypted emails. The vulnerability allows hackers to read an encrypted email by making changes to its HTML, which essentially tricks the affected email applications into decrypting the rest of the message.