Apple Patches Critical Hide My Email Vulnerability

Apple Hide My Email vulnerability privacy flaw exposing real email addresses

A Persistent Privacy Breach

A security feature engineered to safeguard authentic email credentials inadvertently disclosed them to external senders for over a year. Apple resolved a severe flaw within its “Hide My Email” service only after extensive media coverage brought the issue to public light, despite receiving initial warnings as early as June 2025. You can review the comprehensive investigative report detailing how Apple fixes Hide My Email vulnerability after 404 Media coverage.

The functionality forms an integral component of the premium iCloud+ subscription, generating randomized aliases under the icloud.com domain. Users utilize these pseudonyms across various digital platforms, shielding their primary email addresses while incoming correspondence is seamlessly forwarded to their actual inbox.

Mechanics of the Exposure

Tyler Murphy, co-founder of the privacy service EasyOptOuts, discovered that any sender could unmask a user’s hidden email address. During initial testing, the exploit proved effective across all evaluated instances. Murphy noted that the flaw impacted 100% of tested “Hide My Email” aliases provided by volunteers.

Unmasking a user’s true identity required sending an email that the receiving mail system rejected as spam or unwanted traffic. The resulting error message or delivery failure log frequently exposed the underlying destination address that the feature was supposed to conceal. In many instances, messages were rejected automatically without reaching the user’s spam folder, leaving individuals unaware that their personal data had been compromised.

Delayed Remediation and Class-Action Litigation

Murphy initially alerted Apple to the security flaw in June 2025. Although the tech giant repeatedly claimed to be investigating or remediating the issue, subsequent testing revealed that the vulnerability persisted. After a year of inaction, Murphy contacted 404 Media, which reported on the flaw in early July while withholding technical specifics until a patch was issued.

Apple officially announced the complete resolution of the vulnerability on July 3, 2026. Nevertheless, security experts at EasyOptOuts warn that residual risks remain. Because email routing logs are often retained by third-party servers for extended periods, exposed primary addresses may linger in external databases.

The researchers advise users to consider all real email addresses associated with aliases created prior to July 7, 2026, as potentially compromised. Following these public disclosures, a class-action lawsuit was filed against Apple. The plaintiffs demand full subscription refunds for affected iCloud+ users and seek an injunction prohibiting the company from misrepresenting its privacy protections.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply