Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC

Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any (TL-2026-2891), also tracked as iCloud Mail From-header spoofing, is a medium-severity software vulnerability, first published 2026-10-04. It has no confirmed attribution, affects Apple iCloud Mail (SMTP submission infrastructure, smtp.mail.me.com), maps to 5 MITRE ATT&CK techniques (T1566, T1585.002, T1598), and is covered by 9 detection rules and 8 indicators of compromise.

Key facts for TL-2026-2891

Threat ID
TL-2026-2891
Also known as
iCloud Mail From-header spoofing, From: anyone@icloud.com
Severity
MEDIUM
Status
PATCHED
Category
VULNERABILITY
First published
2026-10-04
Last reviewed
2026-10-04
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, finance, government administration, consumer
Target regions
Global
Detection rules
9
Indicators of compromise
8

Malware and tooling in Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any

Malware and tooling: smtpsmuggling.com test tooling

Two email spoofing flaws in Apple's iCloud SMTP submission pipeline, found by Timo Longin of SEC Consult Vulnerability Lab, let any holder of a free iCloud account send mail that displayed as any @icloud.com address while passing SPF, DKIM and DMARC. The root cause was parser inconsistency (bare carriage returns in the From: header, then SMTP dot-stuffing handling). Apple has fixed both; no CVE was assigned and no in-the-wild exploitation is reported.

How Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any works

SEC Consult Vulnerability Lab (Timo Longin, known for the 2023 SMTP smuggling research) disclosed two vulnerabilities in Apple iCloud Mail's outbound SMTP infrastructure on 2026-10-01 (blog post 'From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities'; press coverage 2026-10-02). An authenticated user of the submission server smtp.mail.me.com (port 587) normally cannot send with a From: header that differs from their own address; Apple enforces this with a proprietary From-header check that rejects such submissions with '5.7.0 From address is not one of your addresses'. Both flaws bypass that check.

Flaw 1 (carriage-return line-break injection): two internal parsers handle the message differently. Parser 1 (Apple's validation layer) ignores a malformed From header that contains bare CR characters adjacent to the colon (conceptually 'From\r:\radmin@icloud.com') and so validates only the attacker's own legitimate second From header. Parser 2 (suspected Postfix based on message signatures) strips the CRs and normalizes the first header into a valid From header, so the relayed message carries a From header naming the spoofed identity. A multipart/alternative boundary was used to keep the legitimate address from being displayed. Apple's first remediation attempt reportedly relied on substring blacklisting (e.g., of 'admin') and was insufficient.

Flaw 2 (SMTP dot-stuffing inconsistency): after the first fix, the researcher found that Parser 1 does not honor the RFC 5321 section 4.5.2 dot-stuffing removal rules while Parser 2 deletes leading periods. Sequences such as '.:' therefore create an interpretation divergence that again lets a malicious From header pass validation and appear differently after relay.

Authentication still passes because the envelope sender / Return-Path remains the attacker's real iCloud address (SPF passes against Apple's own sending infrastructure, observed from 17.57.155.19), and the DKIM signature is applied after Parser 2 normalization, over the already-spoofed message; DMARC passes through alignment with icloud.com. Recipients therefore see authenticated mail apparently from identities such as tim.cook@icloud.com or no-reply@icloud.com.

Impact is trust abuse: highly credible phishing, payment-fraud/BEC and credential-harvesting mail impersonating Apple or any iCloud user that traverses gateways relying on SPF/DKIM/DMARC. Reported to Apple 2024-05-21; fixes fully rolled out and confirmed 2025-11-12. Apple paid a $15,000 bounty. No CVE or public Apple advisory was identified, no threat actor is named, and no exploitation in the wild is stated. Sourcing note: the hunt summary and the news article say fixes were confirmed in December 2025; the primary SEC Consult report gives 2025-11-12 for full rollout, which is used here. Severity (MEDIUM) and the absence of a CVSS score are analyst estimates.

MITRE ATT&CK techniques used in TL-2026-2891

Initial Access

T1566 Phishing

Resource Development

T1585.002 Email Accounts

Reconnaissance

T1598 Phishing for Information

Stealth

T1684.001 Impersonation; T1684.002 Email Spoofing

Affected products and versions in Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any

  • Apple — iCloud Mail (SMTP submission infrastructure, smtp.mail.me.com)
    Vulnerable versions: Service-side, from at least 2024-05-21 until fixes rolled out; the first fix was released 2025-05-24 but the dot-stuffing variant stayed exploitable
    Fixed in: Fully remediated and confirmed by Apple 2025-11-12

Remediation for Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any

Patches

  • Server-side Apple fix; no CVE and no customer-installable patch

Immediate actions

  • No customer patch action needed for iCloud; Apple fixed the service side (confirmed fully rolled out 2025-11-12)
  • Hunt historical mail from @icloud.com for Return-Path or Authentication-Results identity that differs from the displayed From address
  • Flag messages with multiple From headers, bare CR characters in headers, or unexpected multipart/alternative boundaries containing headers

Workarounds

  • Compare Return-Path with the visible From address when triaging suspicious iCloud-origin mail

Longer-term hardening

  • Do not treat SPF/DKIM/DMARC pass as proof of sender identity for sensitive requests (credentials, payments); require out-of-band verification
  • Gateway rule: reject or quarantine RFC 5322 violations such as multiple From headers
  • For operators of SMTP submission pipelines: validate the From header against the authenticated identity in a single canonical parse (e.g., a milter) and sign DKIM only after all parsing and normalization is complete; do not rely on smtpd_sender_login_maps alone

Weaknesses (CWE) in Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any

CWE-444, CWE-290

Timeline of Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any

  • SEC Consult publishes Timo Longin's SMTP smuggling research, the prior art on SMTP parser differentials that bypass SPF/DKIM/DMARC.
  • Carriage-return From-header spoofing flaw reported to Apple.
  • Apple confirms it has made changes addressing the report.
  • Apple awards a $15,000 Apple Security Bounty.
  • Second spoofing vector (SMTP dot-stuffing inconsistency) discovered, bypassing the first remediation.
  • First fix released; the dot-stuffing variant remained exploitable.
  • CERT/CC publishes VU#517845 on authenticated-user From header spoofing across mail providers (Apple status listed as unknown).
  • Apple confirms fixes fully rolled out (news coverage dates confirmation to December 2025).
  • SEC Consult publishes the technical report 'From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities'.
  • Cyber Security News reports the flaws publicly.

Sources cited for Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any

More in vulnerability

Detection coverage for TL-2026-2891

As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2891 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats