From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
A research collaboration with the SEC Consult Vulnerability Lab has uncovered two new email spoofing vulnerabilities in Apple iCloud's email infrastructure. These discoveries followed the dramatic emergence of SMTP smuggling in 2023, which allowed email spoofing for millions of servers worldwide. SMTP implementations like Postfix, Sendmail, and Exim had patched these vulnerabilities by 2024, prompting researchers to seek alternative methods for email spoofing.
The study delves into the parsing discrepancies in SMTP implementations, focusing on a subclass of email spoofing known as header smuggling. Unlike traditional SMTP smuggling, header smuggling exploits the parsing differences between the From header and the SMTP MAIL FROM command. By manipulating the From header, it is possible to spoof the sender address despite authentication checks that verify the MAIL FROM command's sender address.
The research demonstrates that by exploiting interpretation differences in SMTP implementations, it is possible to send emails as arbitrary icloud.com addresses. Through a series of tests and analysis, the researchers confirm that this spoofing technique remains viable in 2025. This finding highlights the ongoing challenges in ensuring the security and authenticity of email communications, particularly in the face of evolving spoofing vulnerabilities.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.