{
  "id": 12094011,
  "title": "From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities",
  "url": "https://urgent.news/2026/10/05/from-anyone-icloud-com-spoofing-arbitrary-apple-icloud-identities",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-05T06:50:55.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://sec-consult.com/blog/detail/from-anyoneicloudcom-spoofing-arbitrary-apple-icloud-identities/"
  },
  "original_language": "en",
  "account": "A research collaboration with the SEC Consult Vulnerability Lab has uncovered two new email spoofing vulnerabilities in Apple iCloud's email infrastructure. These discoveries followed the dramatic emergence of SMTP smuggling in 2023, which allowed email spoofing for millions of servers worldwide. SMTP implementations like Postfix, Sendmail, and Exim had patched these vulnerabilities by 2024, prompting researchers to seek alternative methods for email spoofing.\n\nThe study delves into the parsing discrepancies in SMTP implementations, focusing on a subclass of email spoofing known as header smuggling. Unlike traditional SMTP smuggling, header smuggling exploits the parsing differences between the From header and the SMTP MAIL FROM command. By manipulating the From header, it is possible to spoof the sender address despite authentication checks that verify the MAIL FROM command's sender address.\n\nThe research demonstrates that by exploiting interpretation differences in SMTP implementations, it is possible to send emails as arbitrary icloud.com addresses. Through a series of tests and analysis, the researchers confirm that this spoofing technique remains viable in 2025. This finding highlights the ongoing challenges in ensuring the security and authenticity of email communications, particularly in the face of evolving spoofing vulnerabilities.",
  "summary": null,
  "key_points": [],
  "editors_take": "This discovery underscores the persistent vulnerability of email systems to spoofing attacks, as exploiters adapt and find new weaknesses, like header smuggling, in implementations meant to prevent them.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}