Pull to refresh
Logo
Apple iCloud Mail bugs let attackers spoof any @icloud.com sender

Apple iCloud Mail bugs let attackers spoof any @icloud.com sender

New Capabilities

Forged messages passed SPF, DKIM, and DMARC after two years of attempted fixes

2 days ago: SEC Consult blog details both bypasses

Overview

Updated 2 hours ago

A free iCloud account let an attacker send mail that appeared to come from tim.cook@icloud.com or any other @icloud.com address. The forged messages passed Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC) — the three authentication checks most mail systems trust to separate real mail from forgery.

SEC Consult researcher Timo Longin found two ways to exploit parsing differences between components inside Apple's mail infrastructure, a technique he calls header smuggling. Apple paid a $15,000 bounty, shipped a fix that failed, and confirmed a complete remediation in December 2025. The saga shows that passing authentication checks does not prove who sent an email.

Why it matters

Spoofed mail that passes SPF, DKIM, and DMARC defeats the defenses most companies rely on against phishing — these bugs made iCloud a trusted disguise.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

$15,000
Bug bounty paid by Apple
Awarded in November 2024 for the initial From-header bypass report.
567 days
Time from first report to confirmed fix
First issue reported May 21, 2024; Apple verified full remediation December 9, 2025.
3
Email authentication checks bypassed
SPF, DKIM, and DMARC all passed on spoofed messages.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

May 2024 October 2026

7 events Latest: 2 days ago
Tap a bar to jump to that date
  1. SEC Consult blog details both bypasses

    Latest Publication

    The blog post describing both header-smuggling methods circulates to the security community.

  2. Full technical disclosure posted

    Publication

    SEC Consult posts the technical writeup to the full-disclosure mailing list.

  3. Remediation confirmed

    Fix

    Apple confirms full remediation; SEC Consult verifies the fix works.

  4. Apple's fix fails

    Fix

    Apple deploys an update that does not eliminate the bypass.

  5. Second bypass discovered

    Disclosure

    Longin finds a dot-stuffing handling flaw that bypasses Apple's hardening, and reports it.

  6. Apple pays $15,000 bounty

    Reward

    Apple awards the bounty for the initial From-header report.

  7. First spoofing bypass reported to Apple

    Disclosure

    Longin reports the From-header smuggling bypass via bare carriage returns.

Scenarios

1

Similar header-smuggling flaw found in another provider

Possible Resolves by Oct 5, 2027

Discussed by: SEC Consult, which states the iCloud case is not isolated and spoofing keeps resurfacing across providers

Another email provider's infrastructure contains an analogous parsing bug that lets an authenticated user forge a sender address while passing authentication checks. It surfaces either through independent research or a vendor-triggered fix and disclosure.

2

Apple ships additional mail-hardening updates

Likely Resolves by Apr 5, 2027

Discussed by: The disclosure record, which documents multiple failed fixes before final remediation

Apple extends the header-parsing lessons across its wider mail infrastructure and issues further security updates addressing the SMTP handling attack surface beyond the two reported bugs.

3

iCloud spoofing exploited in phishing campaigns

Unlikely Resolves by Oct 5, 2027

Discussed by: SEC Consult, which notes provider-aware filtering could flag spoofed traces that authentication checks miss

Threat-intel vendors report in-the-wild phishing campaigns that used the iCloud sender-spoofing technique before the full remediation reached all of Apple's infrastructure. The spoofed messages would have impersonated Apple or individual iCloud users.

Historical Context

2 moments from history that rhyme with this story — and how they unfolded.

2023-2024

SMTP smuggling (2023)

Timo Longin showed that outbound and inbound email servers parse message data differently, letting attackers smuggle extra content past security scanners. The technique affected major providers before patches landed.

Then

Major mail providers deployed fixes for the parsing gaps.

Now

The research established SMTP parsing discrepancies as a repeatable bug class and produced the techniques behind the iCloud findings.

Why this matters now

Same researcher, same root cause: servers that interpret the same message differently. The iCloud flaws are the direct follow-on.

2000s-2010s

The rise of email authentication (2000s-2010s)

Email was designed with no sender authentication, so anyone could put any address in the From field. Standards bodies introduced SPF, DKIM, and DMARC during the 2000s and 2010s to let receivers verify that mail really came from the domain it claimed.

Then

The standards sharply reduced trivial spoofing and became the backbone of phishing defenses.

Now

They authenticate domains, not individual mailboxes, and they can be defeated by parsing bugs inside a provider — exactly what the iCloud flaws did.

Why this matters now

The iCloud spoofs passed all three checks, showing these protocols still trust the infrastructure they are meant to police.

Sources

(6)