Header smuggling flaw let researchers spoof any iCloud sender, netting $15,000 bounty

evilsocket · x · 2026-10-01

SEC Consult researcher Timo Longin (known for SMTP smuggling) disclosed two email spoofing vulnerabilities in Apple iCloud's mail infrastructure. The "header smuggling" technique exploits parsing discrepancies in iCloud's SMTP services, allowing attackers to send emails from arbitrary icloud.com addresses (e.g. [email protected]) that pass SPF checks. The post recaps the 2023 SMTP smuggling wave and 2024 fixes, noting parsing inconsistencies remain a risk to email trust. Apple paid a $15,000 bounty.

Original post →

More from Safety

Safety channel →