Mail in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to trigger a refresh operation, and consequently cause a visit to an arbitrary web site, via a crafted HTML e-mail message.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/jankais3r/iOS-Mail.app-inject-kit