Vulnerability
Published 2026-10-01
Verified 2026-10-03

Apple iCloud Mail (SEC Consult 1 Oct): free-account From-header smuggling passed SPF/DKIM/DMARC — fixed; $15k bounty

SEC Consult Vulnerability Lab blog (1 October 2026; researcher Timo Longin) details two From-header smuggling flaws in Apple iCloud’s outbound SMTP processing that let an authenticated free iCloud account send mail appearing to come from arbitrary @icloud.com addresses (examples include high-value identities such as tim.cook@icloud.com or no-reply@icloud.com) while receiving systems still recorded SPF, DKIM, and DMARC pass. Root cause: inconsistent parsing between iCloud’s outbound validators and later cleanup/relay stages (carriage-return / line-break tricks in the From: header; SMTP dot-stuffing / “dot-peeling” discrepancies). SPF passed because Apple’s legitimate infrastructure sent the message; DKIM passed because iCloud signed after the affected stage; DMARC passed on icloud.com alignment. Carriage-return issue first reported to Apple 21 May 2024; Apple adjusted handling; researchers found a second bypass; final fixes confirmed December 2025; public write-up 1 Oct 2026. Apple Security Bounty awarded US$15,000. No CVE id assigned in the SEC Consult blog. Wires: Cyber Security News / SecurityWeek “In Other News” 2 Oct. Primary: SEC Consult blog.

Product
Apple iCloud Mail outbound SMTP / From-header handling
Versions
Vulnerable behaviour in iCloud outbound pipeline as of researcher reports (2024–2025); Apple confirmed fixes by December 2025 per SEC Consult. No public CVE id in primary write-up.
Exploited in Australia?
unknown
Patch to
End users: no client patch — Apple fixed server-side. Defenders: do not treat SPF+DKIM+DMARC pass alone as proof of human-trusted sender identity for icloud.com; inspect Return-Path vs visible From; flag unexpected no-reply@ / executive-looking iCloud senders in high-value workflows. Mail gateway teams: retain full headers for spoof investigations.

Primary: SEC Consult — From: anyone@icloud.com — Spoofing Arbitrary Apple iCloud Identities (1 Oct 2026) · Vendor: Apple — security releases index (HT201222; watch for matching Mail/iCloud notes) · SecurityWeek — In Other News: $15K iCloud spoofing bugs (2 Oct 2026)

vulnerabilities identity email apple