Apple iCloud Mail flaws allowed sender spoofing that passed security checks
Brief
Two vulnerabilities in Apple’s iCloud Mail infrastructure let an authenticated user send messages that appeared to come from any @icloud. com address while passing SPF, DKIM, and DMARC checks. The findings were published by Timo Longin, a principal security consultant at SEC Consult, known for his earlier research into SMTP smuggling. Longin discovered the flaws during …
The post Apple iCloud Mail flaws allowed sender spoofing that passed security checks appeared first on CyberInsider .
