Italian security researcher Michele Spagnuolo has published a video showing how the flaw can be exploited in various ways. The flaw allows apps to be automatically opened by viewing an email in Mailbox, or sending messages via Twitter or SMS. The makers of the Mailbox app have been aware of the security hole since May 2013, but the vulnerability is still there. Mailboxs PR team have been in touch and understandably are attempting to downplay the potential seriousness of the flaw.”]
Source: https://grahamcluley.com/mailbox-iphone-app-javascript-flaw/