SEC Consult researcher Timo Longin disclosed two flaws in Apple iCloud Mail's outbound SMTP processing that allowed a holder of a free iCloud account to send email impersonating arbitrary @icloud.com addresses. The issues abused inconsistent parsing of message fields, including unusual carriage-return characters in the From header and differing handling of SMTP dot-stuffing. Messages were relayed through legitimate Apple infrastructure, allowing them to pass SPF, DKIM, and DMARC checks and appear authenticated to recipients.
SEC Consult initially reported one flaw to Apple on May 21, 2024, then found a bypass after Apple altered handling of the original proof of concept. Apple confirmed final remediation in December 2025 and awarded Longin a $15,000 Apple Security Bounty; SEC Consult published the technical details on October 1, 2026. The flaws could have enabled highly convincing phishing or business-email-compromise messages that evaded common email-authentication defenses.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
SEC Consult published its technical report describing two iCloud Mail SMTP-processing flaws that let free iCloud accounts send authenticated-looking email as arbitrary @icloud.com identities.
Apple confirmed that both iCloud Mail email-spoofing issues had been finally remediated.
On June 13, 2025, SEC Consult confirmed that an iCloud Mail sender-spoofing bypass remained exploitable despite an update Apple reported on May 24. The attempted remediation therefore did not fully resolve the vulnerability.
Timo Longin of SEC Consult reported a carriage-return parsing flaw in Apple iCloud Mail that could bypass sender-address validation and enable arbitrary @icloud.com sender spoofing.
Apple awarded Timo Longin a $15,000 Apple Security Bounty for the iCloud Mail spoofing findings.
After Apple changed its handling of the original proof of concept, SEC Consult identified another bypass based on inconsistent SMTP dot-stuffing parsing. It likewise enabled unauthorized @icloud.com sender impersonation through Apple infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcereddit.com
Open sourcesec-consult.com
Open sourceusenix.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.