Apple Patched iCloud Mail Flaws That Spoofed Any Sender
SEC Consult found two patched iCloud mail flaws letting free accounts spoof any @icloud.com sender while passing SPF, DKIM, and DMARC; no CVE was assigned.
Researcher Timo Longin of SEC Consult Vulnerability Lab reported two outbound-mail parsing flaws that let an authenticated free iCloud account send messages appearing to come from any @icloud.com address, including tim.cook@icloud.com. Cyber Security News said one issue abused carriage-return characters in the From header and the other exploited SMTP dot-stuffing, and that spoofed mail passed SPF, DKIM, and DMARC because Apple applied its DKIM signature after the vulnerable processing stage. A Lobsters summary described the same case as two header-smuggling bugs that worked after classic SMTP command smuggling failed against post-2024 server fixes, noted that Apple normally rejects a From address the authenticated user does not own, and tied the research to earlier work tracked as CERT/CC VU#517845. Full Disclosure said the flaw was in iCloud Mail's cloud SMTP submission service rather than a specific client build, that SEC Consult verified Apple's fix on December 9, 2025, and that no CVE was assigned. Sources agree on the researcher, two flaws, arbitrary icloud.com spoofing, a December 2025 fix, a $15,000 bounty, and an October 1, 2026 report, but differ on whether both bugs are header smuggling or one is specifically SMTP dot-stuffing.
- Timo Longin of SEC Consult Vulnerability Lab found two outbound-mail parsing flaws in Apple iCloud.
- Authenticated free accounts could send mail appearing from any @icloud.com address, including tim.cook@icloud.com, and the messages passed SPF, DKIM, and DMARC.
- Cyber Security News said one bug abused carriage returns in the From header and the other SMTP dot-stuffing; Lobsters described both as header smuggling after classic SMTP command smuggling failed against post-2024 fixes.
- Apple signed with DKIM after the vulnerable processing stage, so spoofed mail passed authentication; Apple normally rejects a From address the account does not own.
- Apple's fixes were confirmed in December 2025, and SEC Consult verified the fix on December 9, 2025.
- Longin received a $15,000 bounty, and the technical report was published on October 1, 2026.
- The issue affected iCloud Mail's cloud SMTP submission service rather than a specific client build, and no CVE was assigned.
- The write-up builds on earlier SMTP smuggling and ambiguous-From research tracked as CERT/CC VU#517845.
Coverage timelineoldest first · each row is one article
- · 6d agoFree iCloud Account Could Let Attackers Spoof Any @icloud.com Address and Pass Email Security Checks
Cyber Security News· 58
Two patched Apple iCloud SMTP parsing flaws let free accounts spoof any @icloud.com address while passing SPF, DKIM, and DMARC checks.
- · 3d agoFrom: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
Lobsters · security· 66
SEC Consult showed header smuggling can spoof arbitrary sender addresses on Apple iCloud.
- · 2d ago