SEC Consult Research 20261001 :: Arbitrary Email sender spoofing in Apple iCloud mail
SEC Consult disclosed sender spoofing in Apple iCloud Mail SMTP; Apple fixed it, with no CVE assigned.
SEC Consult Vulnerability Lab announced an arbitrary email sender-spoofing flaw in Apple iCloud Mail's SMTP submission service. The issue affected iCloud mail infrastructure as a cloud service rather than a specific client build. Apple fixed it, and SEC Consult verified the fix on December 9, 2025. No CVE number was assigned.
40