cyberinsider.com Apple iCloud Mail Vulnerabilities Enable Sender Spoofing
Article Content
- •Two vulnerabilities in iCloud Mail allowed sender spoofing.
- •Attackers could bypass email authentication checks like SPF and DKIM.
- •Final patch for the vulnerabilities was confirmed in December 2025.
Two vulnerabilities in Apple's iCloud Mail infrastructure allowed authenticated users to send emails appearing to originate from any @icloud.com address while passing SPF, DKIM, and DMARC checks. Discovered by Timo Longin of SEC Consult, the flaws involved manipulating email headers using techniques known as 'header smuggling.' The first method exploited malformed From headers with standalone carriage-return characters, while the second used 'dot-stuffing' in SMTP. These methods could facilitate impersonation and phishing attacks without needing access to the spoofed mailbox. Although Apple attempted to patch the vulnerabilities, researchers found bypasses, with a final fix confirmed in December 2025. Users are advised to verify unexpected requests through separate channels, as passing authentication does not guarantee sender identity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Apple in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the attack methods used?
When were these vulnerabilities reported?
What should users do to protect themselves?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetScaler ADC and…