Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
iCloud Email Flaws Allowed Spoofing of Any Address

iCloud Email Flaws Allowed Spoofing of Any Address

Posted on October 2, 2026 By CWS

Recently, security researcher Timo Longin, in collaboration with the SEC Consult Vulnerability Lab, uncovered critical vulnerabilities within Apple’s iCloud email infrastructure. These flaws made it possible for individuals with a free iCloud account to send emails that appeared to originate from any @icloud.com address. This exploitation of the system allowed emails to pass the stringent SPF, DKIM, and DMARC checks, which are fundamental to verifying the sender’s identity in email communications.

Email Authentication Challenges

Apple has since addressed these vulnerabilities after a period of responsible disclosure. The findings underscore that email authentication reliability hinges on the robustness of the systems processing emails before they exit a provider’s network. In this instance, the issue did not stem from compromised iCloud accounts or weaknesses in recipients’ mailboxes. Instead, it arose from discrepancies in how different parts of Apple’s SMTP processing handled the same email data.

The SMTP, or Simple Mail Transfer Protocol, remains a cornerstone of internet email. It involves both an envelope sender, known as MAIL FROM or Return-Path, and a visible From: header that appears in users’ email clients. Typically, iCloud ensures that authenticated accounts only utilize permitted sender addresses. Attempts to alter the visible sender to another iCloud identity would result in an error from Apple’s service, stating the address was unauthorized for the user.

Technical Insights into the Vulnerability

Longin discovered methods to manipulate iCloud’s internal parsers, leading them to interpret messages differently. One issue involved inserting unusual carriage-return characters within the From: header. The initial parser failed to process the altered field as a standard sender header during user validation. However, a subsequent parser corrected the message, presenting it as a valid sender header to receiving mail servers.

The SEC Consult’s technical report revealed the gravity of the situation: users authenticated as one iCloud address could make delivered emails appear to come from another, high-value identities included. Furthermore, a second issue exploited SMTP dot-stuffing rules, with parsers inconsistently applying these rules, allowing spoofed headers to bypass iCloud’s checks.

Implications and Lessons for Email Security

Worryingly, these spoofed emails could pass SPF, DKIM, and DMARC checks. SPF verified that Apple’s legitimate infrastructure dispatched the email, DKIM succeeded due to iCloud’s cryptographic signature application post-processing, and DMARC passed because the visible sender domain matched. These checks are often considered strong proof of email legitimacy by users and mail systems.

The incident highlights potential vulnerabilities in trusted provider-side parsing, which can undermine security protocols. SEC Consult initially reported the issue to Apple in May 2024, leading to final fixes confirmed by December 2025. Apple acknowledged Longin’s findings with a $15,000 reward from its Security Bounty Program.

This case echoes previous SMTP smuggling research, demonstrating how inconsistent protocol handling can enable widespread email spoofing. The broader lesson for cybersecurity teams is clear: while SPF, DKIM, and DMARC are crucial, they do not guarantee complete security. It’s vital to scrutinize full message headers, monitor for discrepancies between visible From: addresses and Return-Paths, and treat unexpected requests with skepticism.

Cyber Security News Tags:Apple, Cybersecurity, DKIM, DMARC, email security, email spoofing, iCloud, SMTP, SPF, Vulnerability

Post navigation

Previous Post: Fake Zoom Installer on macOS Spreads CloudSyncD Malware

Related Posts

State Hackers Exploit RDP Servers to Deploy Stealthy Malware State Hackers Exploit RDP Servers to Deploy Stealthy Malware Cyber Security News
Critical TP-Link Vulnerabilities Demand Immediate Firmware Updates Critical TP-Link Vulnerabilities Demand Immediate Firmware Updates Cyber Security News
Greedy Sponge Hackers Attacking Financial Institutions With Modified Version of AllaKore RAT Greedy Sponge Hackers Attacking Financial Institutions With Modified Version of AllaKore RAT Cyber Security News
Hackers Target TrueConf Servers with Malware Hackers Target TrueConf Servers with Malware Cyber Security News
AI-Powered Forg365 Platform Targets Microsoft 365 Accounts AI-Powered Forg365 Platform Targets Microsoft 365 Accounts Cyber Security News
Conti Group Member Responsible for Deploying Ransomware Extradited to USA Conti Group Member Responsible for Deploying Ransomware Extradited to USA Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware
  • OpenAI Dismisses Safety Team Members Over Data Breach
  • Exploited Zammad Flaws Enable Remote Code Execution
  • Microsoft’s X Account Breached in Crypto Scam

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware
  • OpenAI Dismisses Safety Team Members Over Data Breach
  • Exploited Zammad Flaws Enable Remote Code Execution
  • Microsoft’s X Account Breached in Crypto Scam

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark