SEC Consult Research 20261001 :: Arbitrary Email sender spoofing in Apple iCloud mail
Full Disclosuremailing list archivesFrom: SEC Consult Vulnerability Lab via Full 2026-10-6 17:44:42 Author: seclists.org(查看原文) 阅读量:1 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: SEC Consult Vulnerability Lab via Fulldisclosure <fulldisclosure () seclists org>
Date: Thu, 1 Oct 2026 12:08:33 +0000

SEC Consult Vulnerability Lab Research Announcement < 20261001 >
=======================================================================
              title: Arbitrary Email sender spoofing in Apple iCloud mail
            product: Apple iCloud mail (SMTP submission service)
 vulnerable version: iCloud mail infrastructure (cloud service)
      fixed version: Fixed by Apple (verified by SEC Consult, 2025-12-09)
         CVE number: None assigned
             impact: Sending of emails from arbitrary icloud.com addresses,
                     passing SPF, DKIM and DMARC checks
           homepage: https://www.apple.com/
           reported: 2024-05-21 (issue 1), 2024-12-07 (issue 2)
                 by: Timo Longin (Office Vienna)
                     SEC Consult Vulnerability Lab

                     An integrated part of SEC Consult, an Atos business
                     Europe | Asia

                     https://www.sec-consult.com

=======================================================================

Summary:
--------
The SEC Consult Vulnerability Lab has published a blog post about two
email spoofing vulnerabilities in Apple's iCloud mail infrastructure.
They allowed an authenticated iCloud user to send emails from arbitrary
icloud.com addresses. The spoofed messages passed SPF, DKIM and DMARC
checks at the receiving side. The research builds on SMTP smuggling.


Blog URL:
---------
Full technical details here:
https://r.sec-consult.com/icloud


Vulnerability overview/description:
-----------------------------------
1) From header smuggling via bare CR characters
iCloud's SMTP submission services handle a From header containing bare
CR characters differently in two internal components. The component
that authenticates the sender ignores the manipulated header, while a
second component, which is likely Postfix-based, replaces standalone CR
characters with CR LF. This pushes the legitimate From header into the
message body and leaves the attacker-controlled From header as the one
seen by the receiver.

2) From header smuggling via dot-stuffing handling ("dot-peeling")
After Apple hardened the From header parsing of the first component, a
second bypass was found. The first component does not honor the
dot-stuffing rules of RFC 5321 section 4.5.2, which allowed the
separation of header and body to be abused in the second component.


Impact:
-------
Both issues allowed sending emails as arbitrary icloud.com addresses.
DKIM signatures are created after the message has been processed by the
second component, therefore SPF, DKIM and DMARC checks all passed on the
receiving side.


Vendor contact timeline:
------------------------
2024-05-21: Initial vulnerability report submitted to Apple: icloud.com SMTP
            services can be abused via CRLF injection in the From: header to
            send spoofed emails (e.g., admin () icloud com) with valid DKIM/DMARC.
            PoC files and script attached; credit line requested for Timo Longin
            / SEC Consult Vulnerability Lab.
2024-06-06: Follow-up requesting a status update and fix timeline; Apple
            responds that the issue is still under investigation and asks that
            details not be disclosed until fixed.
2024-06-27: Follow-up requesting a status update.
2024-06-29: Apple reports no new status update.
2024-08-01: SEC Consult confirms the PoC script no longer works and asks Apple
            to confirm a fix was made.
2024-08-09: Apple reports no new status update, thanks SEC Consult for patience.
2024-09-01: Follow-up requesting a status update.
2024-09-11: Apple reports still investigating, no new updates to share.
2024-10-07: Follow-up checking the issue hasn't been forgotten.
2024-10-08: SEC Consult notes an upcoming SMTP smuggling talk at IT-SECX (Oct
            11) that will not disclose new vulnerability details; asks Apple for
            a fix timeline.
2024-10-17: Apple states changes have been made and asks SEC Consult to confirm
            current behavior.
2024-11-01: SEC Consult confirms the original PoC (CRLF injection in From:
            header) is no longer exploitable; proposes public disclosure at
            BSidesVienna on Nov 23, 2024, plus a blog post in December.
2024-11-04: Apple confirms the report as remediated and asks to review a draft
            of the planned disclosure.
2024-11-07: Draft BSidesVienna slides shared with Apple (attachment failed to
            send).
2024-11-09: Apple reports the attachment wasn't received; asks SEC Consult to
            resend.
2024-11-11: Slides resent; SEC Consult asks Apple for root-cause details
            (proprietary iCloud SMTP vs. third-party software).
2024-11-19: Apple confirms the report qualifies for the Apple Security Bounty
            and awards $15,000.
2024-12-06: SEC Consult discovers a second, related parsing issue enabling
            From-header spoofing via a different method; Apple asks that it be
            filed as a separate report.
2024-12-07: New report opened and tracked as OE196504222209; Apple acknowledges
            receipt.
2024-12-11: SEC Consult reports the deployed fix is insufficient - it merely
            blacklists the POC substring "admin" in the From: header rather than
            fixing the root parsing flaw, leaving most other @icloud.com
            addresses spoofable and potentially breaking mail for legitimate
            users with "admin" somewhere in their address.
2024-12-12: SEC Consult provides a new working PoC spoofing security () icloud com,
            with supporting screenshots, raw message, and script.
2024-12-16: Apple acknowledges the additional information and states it will
            follow up if further details are needed.
2025-01-28: SEC Consult shares further technical analysis, noting Postfix's
            smtpd_sender_login_maps limitations and recommending a Milter-based
            filter (e.g., milterfrom) that checks the From: header against the
            final email data before sending, as a likely root-cause fix.
2025-01-29: Apple acknowledges the analysis, states the issue is still under
            investigation.
2025-03-28: SEC Consult confirms the vulnerability is still exploitable. Apple
            replies (marked confidential) that a fix is planned for a future
            security update and asks that disclosure wait until it ships.
2025-04-04: SEC Consult agrees to hold disclosure and asks for a rough
            timeframe; Apple says more information will be available in the
            coming weeks.
2025-05-22: SEC Consult asks for an update, noting the issue remains
            exploitable.
2025-05-24: Apple reports an update was released in the prior 48 hours and asks
            SEC Consult to reassess whether the issue is remediated.
2025-06-10: Apple follows up again asking SEC Consult to confirm whether the
            update fixed the issue.
2025-06-13: SEC Consult confirms a bypass still exists, working the same way as
            described in report OE196504222209; Apple acknowledges and says it
            will review.
2025-07-17: SEC Consult asks for a fix update, noting a conference talk planned
            in about two months.
2025-07-22: Apple states the issue is still under investigation and reminds SEC
            Consult that bounty eligibility requires no public disclosure before
            an update ships with a security advisory.
2025-09-10: SEC Consult reports the conference talk was cancelled and asks for a
            status update.
2025-09-12: Apple replies (marked confidential) that a fix is planned for a
            future security update "in the near future" and again asks for
            continued non-disclosure.
2025-10-08: SEC Consult reports the vulnerability is still exploitable and asks
            whether the update has shipped.
2025-10-10: Apple states changes are being implemented and more information will
            follow soon.
2025-11-11: SEC Consult confirms the previous PoC spoofing method no longer
            works; asks Apple to confirm the fix is fully rolled out.
2025-11-12: Apple confirms the updates have been pushed out and asks SEC Consult
            to review.
2025-11-14: SEC Consult confirms they will review the fix.
2025-12-09: SEC Consult confirms the deployed fixes remediate the original
            issue.
2026-10-01: Public release of blog post.



Solution:
---------
Apple has fixed the vulnerabilities in its iCloud mail infrastructure.
No CVE was assigned.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SEC Consult Vulnerability Lab
An integrated part of SEC Consult, an Atos business
Europe | Asia

About SEC Consult Vulnerability Lab
The SEC Consult Vulnerability Lab is an integrated part of SEC Consult, an
Atos business. It ensures the continued knowledge gain of SEC Consult in the
field of network and application security to stay ahead of the attacker. The
SEC Consult Vulnerability Lab supports high-quality penetration testing and
the evaluation of new offensive and defensive technologies for our customers.
Hence our customers obtain the most current information about vulnerabilities
and valid recommendation about the risk profile of new technologies.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Interested to work with the experts of SEC Consult?
Send us your application https://sec-consult.com/career/

Interested in improving your cyber security with the experts of SEC Consult?
Contact our local offices https://sec-consult.com/contact/
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Mail: security-research at sec-consult dot com
Web: https://www.sec-consult.com
Blog: https://blog.sec-consult.com
X: https://x.com/sec_consult

EOF Timo Longin / @2026

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:

  • SEC Consult Research 20261001 :: Arbitrary Email sender spoofing in Apple iCloud mail SEC Consult Vulnerability Lab via Fulldisclosure (Oct 06)

文章来源: https://seclists.org/fulldisclosure/2026/Oct/1
如有侵权请联系:admin#unsafe.sh