Header smuggling flaw let researchers spoof any iCloud sender, netting $15,000 bounty
evilsocket · x · 2026-10-01
SEC Consult researcher Timo Longin (known for SMTP smuggling) disclosed two email spoofing vulnerabilities in Apple iCloud's mail infrastructure. The "header smuggling" technique exploits parsing discrepancies in iCloud's SMTP services, allowing attackers to send emails from arbitrary icloud.com addresses (e.g. [email protected]) that pass SPF checks. The post recaps the 2023 SMTP smuggling wave and 2024 fixes, noting parsing inconsistencies remain a risk to email trust. Apple paid a $15,000 bounty.
More from Safety
- Flag Game paper uses a flag-guessing toy model to trace how AI agent swarms spread shared misconceptions — Hidenori8Tanaka · 2026-10-02
- OpenSwitchboard: open-source MCP server gates agent commitments behind human presses — EnvironmentalRice348 · 2026-10-02
- Buyers now fill out export control declarations when purchasing RTX 5090s in stores — blelbach · 2026-10-02
- Viral analogy asks: why do we release AI like cars, with liability only after failure — aronchick · 2026-10-02
- Ex-OpenAI policy lead: we may never eval dangerous AI capabilities well enough — RosieCampbell · 2026-10-02
- Trump likely to pick Jay Clayton as White House AI czar, CBS News reports — ShakeelHashim · 2026-10-02