Skip to content

Security1 publisher1 min readPublished

iCloud Mail header-smuggling flaws let users forge any @icloud.com sender past DMARC

SEC Consult's Timo Longin found two iCloud Mail flaws letting any signed-in user send SPF-, DKIM- and DMARC-passing mail as any @icloud.com address. A filter that read only those verdicts could not tell the forgeries from mail the real address owner sent.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying iCloud Mail header-smuggling flaws let users forge any @icloud.com sender past DMARC
Generated illustration

What happened

  • The first technique used From headers broken with standalone carriage returns; Apple's sender check ignored them, and later normalization turned them into the attacker's chosen address.
  • The second technique abused SMTP dot-stuffing, where Apple's components processed periods differently and a disguised From header became active.
  • Researchers bypassed Apple's first patches, and a final fix was confirmed in December 2025.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Until the December 2025 fix, a DMARC pass on @icloud.com mail did not establish which iCloud user had sent it, so trust rules built on authentication verdicts were wrong for that domain.
  • exposure Anyone with an iCloud login could pose as a specific iCloud contact without first breaking into that contact's account.
  • decision Reviewing past @icloud.com mail for this abuse means parsing iCloud's raw headers and comparing the authenticated sender trace with the displayed From, since the authentication results cannot answer the question.
  • precedent Because researchers bypassed Apple's first patches, defenders have grounds to retest vendor fixes for header-parsing bugs before trusting a 'fixed' notice.

Both techniques depend on one disagreement inside Apple's pipeline. The component that checked the sender and the processing that later produced the visible From line did not interpret the same header the same way [10]. A carriage-return trick and a dot-stuffing trick look unrelated, and both ended at a forged From address that Apple's own check had let through [3][4]. The techniques are termed "header smuggling" [5].

While the flaws were open, exploitation was cheap. The attacker signed in to iCloud Mail with their own account and never needed access to the mailbox being impersonated [1][5]. Any @icloud.com address could be made to appear as the sender [1].

The public record is a single chain. SC World summarised a Cyber Insider report on research by Timo Longin of SEC Consult [9][2]. The brief does not list CVE identifiers, the date Apple was first notified, or any evidence that attackers used the techniques against real targets [9].

SPF, DKIM and DMARC all passed on the forged messages [1]. According to the report, the raw headers still held traces of the authenticated sender, and filtering that knows how a given provider writes those headers could detect the discrepancy [7].

The report's advice to recipients is to confirm unexpected requests through a separate channel, because passing authentication does not guarantee sender identity [8].

What to watch

  • CVE identifiers or a full disclosure timeline from SEC Consult or Apple, including when the bypassed patches shipped.
  • Testing of other mail providers for the same carriage-return or dot-stuffing disagreement between sender checks and later header processing.
  • Any report that the techniques were used against real targets before the December 2025 fix.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories