As reported by Cyber Insider, two vulnerabilities discovered in Apple’s iCloud Mail infrastructure allowed authenticated users to send emails that appeared to originate from any @icloud.com address, while still passing crucial email authentication checks like SPF, DKIM, and DMARC.
The flaws, identified by Timo Longin of SEC Consult, involved manipulating email headers to alter the displayed sender address. The first method utilized malformed From headers with standalone carriage-return characters, which were initially ignored by Apple's sender checks but later normalized to display the attacker's chosen address. A second technique exploited "dot-stuffing" in SMTP, where differences in how Apple's components processed periods allowed a disguised From header to become active. These techniques, termed "header smuggling," could facilitate convincing impersonation and phishing attacks without needing access to the spoofed mailbox. Despite Apple's attempts to patch the vulnerabilities, researchers found bypasses, with a final fix confirmed in December 2025. While messages passed authentication, raw headers still contained traces of the authenticated sender, suggesting provider-aware filtering could detect discrepancies. Users are advised to verify unexpected requests through separate channels, as passing authentication does not guarantee sender identity.
Source: Cyber Insider
