Skip to content
Apple iCloud Mail Vulnerabilities Enable Sender Spoofing

Apple iCloud Mail Vulnerabilities Enable Sender Spoofing

First seen 5 Oct 2026, 23:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 00:27 UTC
  • •Two vulnerabilities in iCloud Mail allowed sender spoofing.
  • •Attackers could bypass email authentication checks like SPF and DKIM.
  • •Final patch for the vulnerabilities was confirmed in December 2025.

Two vulnerabilities in Apple's iCloud Mail infrastructure allowed authenticated users to send emails appearing to originate from any @icloud.com address while passing SPF, DKIM, and DMARC checks. Discovered by Timo Longin of SEC Consult, the flaws involved manipulating email headers using techniques known as 'header smuggling.' The first method exploited malformed From headers with standalone carriage-return characters, while the second used 'dot-stuffing' in SMTP. These methods could facilitate impersonation and phishing attacks without needing access to the spoofed mailbox. Although Apple attempted to patch the vulnerabilities, researchers found bypasses, with a final fix confirmed in December 2025. Users are advised to verify unexpected requests through separate channels, as passing authentication does not guarantee sender identity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-05-01
Vulnerabilities reported to Apple
Timo Longin reported the sender spoofing vulnerabilities to Apple during a research project.
Cyber Insider
2025-12-01
Final patch confirmed
Apple confirmed a final fix for the vulnerabilities after multiple bypasses were found.
Scworld

More articles in this cluster (2)

Following this threat?

Track Apple in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the attack methods used?
The vulnerabilities exploited malformed From headers and 'dot-stuffing' in SMTP to spoof sender addresses.
When were these vulnerabilities reported?
The vulnerabilities were reported to Apple in May 2024.
What should users do to protect themselves?
Users should verify unexpected requests through separate channels, as passing authentication does not guarantee sender identity.