A parsing gap let spoofed iCloud mail pass every check

Two flaws in Apple's iCloud mail pipeline let a free account send messages that appeared to come from any address on the domain.

AppleThreat Staff
2 Min Read

Email services lean on three checks, SPF, DKIM and DMARC, to decide whether a message truly came from the domain stamped on it. A pair of bugs inside Apple’s iCloud mail pipeline showed how far that trust can be bent.

A free iCloud account was enough to abuse it. The SEC Consult Vulnerability Lab, which published the technical report, credits researcher Timo Longin with finding two flaws that let a sender forge mail from any address on the domain, among them tim.cook@icloud.com and no-reply@icloud.com. Apple has since closed both. What went wrong was not a hijacked login or a careless recipient: Apple’s outbound SMTP path routes a message through several stages, and those stages disagreed about what its headers said. One stage validated the visible sender, while a later one rewrote and forwarded the field. One trick planted stray carriage-return characters in the From line, which the first check skipped because it did not read the field as a normal sender header. The other leaned on SMTP dot-stuffing, the rule covering lines that start with a period, applied differently at each stage. Either way, a forged header that failed the first inspection re-emerged in cleaned form once the message left Apple’s servers.

Recipients received the mail with genuine iCloud authentication attached. SecurityWeek put the combined bounty at $15,000. The lesson is that a signature proves nothing if the pipeline preparing a message can be made to describe the sender in two different ways.

Share This Article