SEC Consult researcher Timo Longin disclosed two flaws in Apple iCloud Mail's outbound SMTP processing that allowed a holder of a free iCloud account to send email impersonating arbitrary @icloud.com addresses. The issues abused inconsistent parsing of message fields, including unusual carriage-return characters in the From header and differing handling of SMTP dot-stuffing. Messages were relayed through legitimate Apple infrastructure, allowing them to pass SPF, DKIM, and DMARC checks and appear authenticated to recipients.
SEC Consult initially reported one flaw to Apple on May 21, 2024, then found a bypass after Apple altered handling of the original proof of concept. Apple confirmed final remediation in December 2025 and awarded Longin a $15,000 Apple Security Bounty; SEC Consult published the technical details on October 1, 2026. The flaws could have enabled highly convincing phishing or business-email-compromise messages that evaded common email-authentication defenses.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
SEC Consult published its technical report describing two iCloud Mail SMTP-processing flaws that let free iCloud accounts send authenticated-looking email as arbitrary @icloud.com identities.
Apple confirmed that both iCloud Mail email-spoofing issues had been finally remediated.
Timo Longin of SEC Consult reported a carriage-return parsing flaw in Apple iCloud Mail that could bypass sender-address validation and enable arbitrary @icloud.com sender spoofing.
Apple awarded Timo Longin a $15,000 Apple Security Bounty for the iCloud Mail spoofing findings.
After Apple changed its handling of the original proof of concept, SEC Consult identified another bypass based on inconsistent SMTP dot-stuffing parsing. It likewise enabled unauthorized @icloud.com sender impersonation through Apple infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.