Edison says this only affected a “small percent” of users

May 17, 2020 07:24 GMT  ·  By

A recently-spotted bug in the Edison Mail app for iOS caused accounts and messages to show up on the devices used by other people.

As it turns out, the whole issue was triggered by an update that brought a sync feature to the Edison email client, essentially allowing users to sync their accounts across devices.

But according to some users who took to Twitter to report the problem, they were able to access accounts and read messages of other people without even providing the password.

“I just updated @Edison_apps Mail &, after enabling a new sync feature, an email account THAT IS NOT MINE showed up in the app, that I could seemingly axcess [sic] completely. This is a SIGNIFICANT security issue. Accessing another's email w/o credentials! Never trusting this app again,” someone says on Twitter.

Update reverted already

Edison has already responded in a tweet, explaining that it’s indeed a bug, but only a small number of users were affected. The company reverted the software update, it said, so everything should be back to normal, which means that your email messages are safe now. Furthermore, Edison says it’s now trying to contact those users who think they might have been affected by this issue, although at this point it’s not clear what action is recommended given the accounts could be accessed even without providing the password.

“We are urgently working to resolve this technical problem in Edison Mail. Yesterday a software update rolled out to a small percent of our users. We have reverted that now and are reaching out to users who have been impacted as fast as we can,” the company said.

Without a doubt, the issue is worrying for many users, especially because the sync feature itself is actually one essential capability that an email client should have.