Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC
Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any (TL-2026-2891), also tracked as iCloud Mail From-header spoofing, is a medium-severity software vulnerability, first published 2026-10-04. It has no confirmed attribution, affects Apple iCloud Mail (SMTP submission infrastructure, smtp.mail.me.com), maps to 5 MITRE ATT&CK techniques (T1566, T1585.002, T1598), and is covered by 9 detection rules and 8 indicators of compromise.
Key facts for TL-2026-2891
- Threat ID
- TL-2026-2891
- Also known as
- iCloud Mail From-header spoofing, From: anyone@icloud.com
- Severity
- MEDIUM
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-10-04
- Last reviewed
- 2026-10-04
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, finance, government administration, consumer
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 8
Malware and tooling in Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any
Malware and tooling: smtpsmuggling.com test tooling
Two email spoofing flaws in Apple's iCloud SMTP submission pipeline, found by Timo Longin of SEC Consult Vulnerability Lab, let any holder of a free iCloud account send mail that displayed as any @icloud.com address while passing SPF, DKIM and DMARC. The root cause was parser inconsistency (bare carriage returns in the From: header, then SMTP dot-stuffing handling). Apple has fixed both; no CVE was assigned and no in-the-wild exploitation is reported.
How Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any works
SEC Consult Vulnerability Lab (Timo Longin, known for the 2023 SMTP smuggling research) disclosed two vulnerabilities in Apple iCloud Mail's outbound SMTP infrastructure on 2026-10-01 (blog post 'From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities'; press coverage 2026-10-02). An authenticated user of the submission server smtp.mail.me.com (port 587) normally cannot send with a From: header that differs from their own address; Apple enforces this with a proprietary From-header check that rejects such submissions with '5.7.0 From address is not one of your addresses'. Both flaws bypass that check.
Flaw 1 (carriage-return line-break injection): two internal parsers handle the message differently. Parser 1 (Apple's validation layer) ignores a malformed From header that contains bare CR characters adjacent to the colon (conceptually 'From\r:\radmin@icloud.com') and so validates only the attacker's own legitimate second From header. Parser 2 (suspected Postfix based on message signatures) strips the CRs and normalizes the first header into a valid From header, so the relayed message carries a From header naming the spoofed identity. A multipart/alternative boundary was used to keep the legitimate address from being displayed. Apple's first remediation attempt reportedly relied on substring blacklisting (e.g., of 'admin') and was insufficient.
Flaw 2 (SMTP dot-stuffing inconsistency): after the first fix, the researcher found that Parser 1 does not honor the RFC 5321 section 4.5.2 dot-stuffing removal rules while Parser 2 deletes leading periods. Sequences such as '.:' therefore create an interpretation divergence that again lets a malicious From header pass validation and appear differently after relay.
Authentication still passes because the envelope sender / Return-Path remains the attacker's real iCloud address (SPF passes against Apple's own sending infrastructure, observed from 17.57.155.19), and the DKIM signature is applied after Parser 2 normalization, over the already-spoofed message; DMARC passes through alignment with icloud.com. Recipients therefore see authenticated mail apparently from identities such as tim.cook@icloud.com or no-reply@icloud.com.
Impact is trust abuse: highly credible phishing, payment-fraud/BEC and credential-harvesting mail impersonating Apple or any iCloud user that traverses gateways relying on SPF/DKIM/DMARC. Reported to Apple 2024-05-21; fixes fully rolled out and confirmed 2025-11-12. Apple paid a $15,000 bounty. No CVE or public Apple advisory was identified, no threat actor is named, and no exploitation in the wild is stated. Sourcing note: the hunt summary and the news article say fixes were confirmed in December 2025; the primary SEC Consult report gives 2025-11-12 for full rollout, which is used here. Severity (MEDIUM) and the absence of a CVSS score are analyst estimates.
MITRE ATT&CK techniques used in TL-2026-2891
Initial Access
Resource Development
Reconnaissance
T1598 Phishing for Information
Stealth
Affected products and versions in Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any
- Apple — iCloud Mail (SMTP submission infrastructure, smtp.mail.me.com)
Vulnerable versions: Service-side, from at least 2024-05-21 until fixes rolled out; the first fix was released 2025-05-24 but the dot-stuffing variant stayed exploitable
Fixed in: Fully remediated and confirmed by Apple 2025-11-12
Remediation for Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any
Patches
- Server-side Apple fix; no CVE and no customer-installable patch
Immediate actions
- No customer patch action needed for iCloud; Apple fixed the service side (confirmed fully rolled out 2025-11-12)
- Hunt historical mail from @icloud.com for Return-Path or Authentication-Results identity that differs from the displayed From address
- Flag messages with multiple From headers, bare CR characters in headers, or unexpected multipart/alternative boundaries containing headers
Workarounds
- Compare Return-Path with the visible From address when triaging suspicious iCloud-origin mail
Longer-term hardening
- Do not treat SPF/DKIM/DMARC pass as proof of sender identity for sensitive requests (credentials, payments); require out-of-band verification
- Gateway rule: reject or quarantine RFC 5322 violations such as multiple From headers
- For operators of SMTP submission pipelines: validate the From header against the authenticated identity in a single canonical parse (e.g., a milter) and sign DKIM only after all parsing and normalization is complete; do not rely on smtpd_sender_login_maps alone
Weaknesses (CWE) in Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any
CWE-444, CWE-290
Timeline of Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any
- SEC Consult publishes Timo Longin's SMTP smuggling research, the prior art on SMTP parser differentials that bypass SPF/DKIM/DMARC.
- Carriage-return From-header spoofing flaw reported to Apple.
- Apple confirms it has made changes addressing the report.
- Apple awards a $15,000 Apple Security Bounty.
- Second spoofing vector (SMTP dot-stuffing inconsistency) discovered, bypassing the first remediation.
- First fix released; the dot-stuffing variant remained exploitable.
- CERT/CC publishes VU#517845 on authenticated-user From header spoofing across mail providers (Apple status listed as unknown).
- Apple confirms fixes fully rolled out (news coverage dates confirmation to December 2025).
- SEC Consult publishes the technical report 'From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities'.
- Cyber Security News reports the flaws publicly.
Sources cited for Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any
- SEC Consult: From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
- Cyber Security News: Free iCloud Account Could Let Attackers Spoof Any @icloud.com Address and Pass Email Security Checks
- SEC Consult: SMTP Smuggling - Spoofing E-Mails Worldwide
- CERT/CC VU#517845: Authenticated SMTP users may spoof other identities due to ambiguous From header interpretation
- MITRE ATT&CK T1672 Email Spoofing
- SMTP Smuggling project page
- RFC 5321 section 4.5.2 (SMTP transparency / dot-stuffing)
- RFC 5322 section 3.6 (single From header requirement)
More in vulnerability
- Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)
- Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft and code execution
- Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to unauthenticated admin access and RCE (CVE-2026-61500) under active exploitation
- Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw
- Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898, CVE-2026-12627)
Detection coverage for TL-2026-2891
As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2891 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.