SEC Consult Research 20261001 :: Arbitrary Email sender spoofing in Apple iCloud mail
SEC Consult disclosed sender spoofing in Apple iCloud Mail SMTP; Apple fixed it, with no CVE assigned.
SEC Consult Vulnerability Lab announced an arbitrary email sender-spoofing flaw in Apple iCloud Mail's SMTP submission service. The issue affected iCloud mail infrastructure as a cloud service rather than a specific client build. Apple fixed it, and SEC Consult verified the fix on December 9, 2025. No CVE number was assigned.
- Arbitrary sender spoofing in Apple iCloud Mail SMTP submission
- Affects iCloud mail cloud infrastructure, not one client build
- Apple fixed it; SEC Consult verified the fix on 2025-12-09
- No CVE number was assigned
Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 06 SEC Consult Vulnerability Lab Research Announcement ======================================================================= title: Arbitrary Email sender spoofing in Apple iCloud mail product: Apple iCloud mail (SMTP submission service) vulnerable version: iCloud mail infrastructure (cloud service) fixed version: Fixed by Apple (verified by SEC Consult, 2025-12-09) CVE number: None...
This source does not provide full text. Read it at seclists.org.