International Edition
Latest News
Technology

SEC Consult: Apple iCloud Mail Flaws Allowed Users to Spoof Any Address

Apple Fixes iCloud Mail Parser Flaws Enabling Sender Spoofing Two vulnerabilities in Apple’s iCloud Mail infrastructure let authenticated users send messages that successfully impersonated arbitrary @icloud.com addresses while passing SPF, DKIM, and DMARC checks, according to research published…

Apple iCloud Mail flaws allowed sender spoofing that passed security checks

Apple Fixes iCloud Mail Parser Flaws Enabling Sender Spoofing

Two vulnerabilities in Apple’s iCloud Mail infrastructure let authenticated users send messages that successfully impersonated arbitrary @icloud.com addresses while passing SPF, DKIM, and DMARC checks, according to research published by SEC Consult. Timo Longin, a principal security consultant at SEC Consult, discovered the flaws during a research project with the SEC Consult Vulnerability Lab and initially reported the security gap to Apple in May 2024. The bypasses allowed attackers to construct convincing phishing emails without needing access to the target mailbox, exploiting discrepancies in how successive software components within Apple’s mail pipeline parsed email headers and SMTP commands.

Parser mismatches enable header smuggling techniques

The security flaws relied on parser mismatches where different parts of Apple’s outgoing infrastructure interpreted message structures inconsistently. The first technique involved standalone carriage-return characters placed inside a malformed From header. Apple’s initial validation stage ignored the malformed header and checked a separate field containing the legitimate, authenticated user address. After Apple deployed partial patches, Longin uncovered a second bypass method utilizing SMTP dot-stuffing, an email transmission convention that adds and removes leading periods. Inconsistent handling of these periods allowed a disguised From header to activate later in the processing pipeline. Because the messages passed through authorized Apple servers, they received valid DKIM signatures after the header transformations occurred, allowing them to clear SPF and DMARC protocols successfully.

iCloud Mail Spoofing – Any @icloud Sender

Insufficient patches fail to resolve vulnerabilities

Apple awarded a $15,000 bug bounty for the initial report in November 2024, but subsequent attempts to fix the vulnerabilities proved insufficient. According to the SEC Consult disclosure timeline, an early remediation attempt merely blocked the substring admin in the From header, leaving addresses like security@icloud.com fully exploitable. An update deployed in May 2025 also failed to completely resolve the parser anomalies.

Frequently Asked Questions About iCloud Mail Spoofing

Why did the spoofed emails pass SPF, DKIM, and DMARC checks?

The messages routed through legitimate Apple servers and received valid digital signatures after internal header transformations altered the visible sender address, satisfying the authentication parameters without verifying mailbox ownership.

What indicators in the email headers could reveal a spoofed message?

Raw email headers retained traces of the authenticated sender, showing a mismatch between the visible From address and the underlying Return-Path address.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”