VYPR
advisoryPublished Oct 2, 2026· 1 source

Free iCloud Accounts Vulnerable to Email Spoofing, Bypassing Authentication

Security researcher Timo Longin discovered flaws in Apple's iCloud mail infrastructure that allowed free account holders to spoof any @icloud.com address and bypass SPF, DKIM, and DMARC checks.

Security researcher Timo Longin, in collaboration with SEC Consult Vulnerability Lab, has revealed two critical email spoofing vulnerabilities within Apple's iCloud mail infrastructure. These flaws enabled an attacker possessing a free iCloud account to craft and send emails that convincingly appeared to originate from any @icloud.com address. Crucially, these spoofed messages were able to bypass established email authentication protocols such as SPF, DKIM, and DMARC, which are fundamental to verifying sender identity and ensuring email integrity.

The vulnerabilities did not stem from compromised accounts or weaknesses in recipient inboxes. Instead, they exploited inconsistencies in how different parts of Apple's outbound SMTP processing pipeline interpreted message data. The core issue lay in the way iCloud's internal parsers handled specific formatting within the email headers, leading to a discrepancy between the initial validation stage and the final message preparation before delivery.

One of the identified flaws involved the use of unusual carriage-return characters within the 'From:' header. Apple's initial parser did not recognize these manipulated characters as indicative of an invalid sender address during the user authentication phase. However, a subsequent parser, responsible for cleaning up the message before it was sent, would interpret these characters differently, effectively sanitizing the header into a valid-looking sender address for the receiving mail server.

The second vulnerability exploited SMTP dot-stuffing rules, a standard protocol mechanism for handling lines that begin with a period. In this instance, the initial iCloud parser and a later parser applied these rules inconsistently. This parsing gap allowed a maliciously crafted 'From:' header to circumvent iCloud's security checks, ultimately appearing as a legitimate sender address to the recipient's mail server.

The implications of these vulnerabilities are significant. The spoofed emails passed SPF checks, confirming that they originated from Apple's legitimate mail infrastructure. They also passed DKIM, as Apple applied its cryptographic signature after the vulnerable message processing stage. Furthermore, DMARC checks were satisfied because the visible sender domain remained '@icloud.com', aligning with Apple's signed message. This combination of passing authentication checks could easily mislead both users and mail gateways into trusting malicious emails.

SEC Consult first reported the carriage-return issue to Apple on May 21, 2024. While Apple addressed the initial proof of concept, researchers discovered a secondary bypass. The final patches were confirmed in December 2025, and the technical report was published on October 1, 2026. For his findings, Longin was awarded a $15,000 Apple Security Bounty.

This case highlights a broader challenge in email security: the reliability of authentication mechanisms like SPF, DKIM, and DMARC is contingent on the secure and consistent implementation of all intermediary systems. Ambiguous parsing of email headers, particularly the 'From:' field, can undermine these protections, allowing authenticated users to impersonate others and bypass expected sender verification. Defenders are reminded that while these protocols are essential, they should not be the sole basis for trust, and vigilance regarding unexpected requests or suspicious content remains paramount.

Synthesized by Vypr AI
Free iCloud Accounts Vulnerable to Email Spoofing, Bypassing Authentication · VYPR