From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities

01.10.2026 research vulnerability

A case study on discovering two email spoofing vulnerabilities in Apple iCloud.

(Image illustration, partially AI-generated)
(Image illustration, partially AI-generated)

(Image illustration, partially AI-generated)

In the course of a research project in collaboration with the SEC Consult Vulnerability Lab, Timo Longin (@timolongin) - known for SMTP smuggling - discovered two exotic email spoofing vulnerabilities in Apple iCloud's emailing infrastructure.

At the end of 2023 SMTP smuggling made a dramatic entrance, allowing email spoofing for millions of email servers worldwide. Ever wanted to send emails as admin@outlook.com while still passing SPF checks? SMTP smuggling had you covered!

However, in 2024, most SMTP implementations adapted, and released security updates for their software. Does this mean the end of SMTP smuggling? Or does this attack have more to offer?