Free iCloud Account Could Let Attackers Spoof Any @icloud.com Address and Pass Email Security Checks
Two patched Apple iCloud SMTP parsing flaws let free accounts spoof any @icloud.com address while passing SPF, DKIM, and DMARC checks.
Researcher Timo Longin with SEC Consult Vulnerability Lab found two iCloud outbound-mail parsing inconsistencies — one abusing carriage-return characters in the From: header, another exploiting SMTP dot-stuffing rules — that let authenticated free accounts send mail appearing from any @icloud.com address, including tim.cook@icloud.com. Spoofed messages passed SPF, DKIM, and DMARC because Apple applied its DKIM signature after the vulnerable processing stage. Apple remediated both flaws with final fixes confirmed in December 2025 and paid Longin a $15,000 bounty; the technical report was published October 1, 2026.