Tue 21 Jul 2026 / 16:26 ET
Kernel
Security 3 min read

Apple says it patched Hide My Email bug that exposed real addresses

Apple told 404 Media it fixed a Hide My Email flaw after public reporting and a class action lawsuit over the paid iCloud+ privacy feature.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

Apple says it patched Hide My Email bug that exposed real addresses
img: 404 Media

Apple says it has fixed a flaw in Hide My Email, the iCloud+ feature meant to shield a user’s actual email address behind an Apple-generated alias. According to 404 Media, the bug let senders work out the real address behind at least some aliases, which cuts directly against the point of paying Apple for the feature.

Apple told 404 Media it deployed a fix on July 3 and said the issue is now fully resolved. The company made that claim after 404 Media reported on the vulnerability in early July. Tyler Murphy, co-founder of EasyOptOuts, had first reported the problem to Apple in June 2025, according to 404 Media.

Hide My Email is included with Apple’s paid iCloud+ subscription. It lets customers create disposable-looking iCloud addresses for signing up to sites, services, or direct email conversations. Messages sent to the alias are forwarded to the customer’s real inbox. The privacy promise is straightforward: the other party should see the alias, not the underlying account.

Murphy found that this separation could fail. He told 404 Media that limited testing with volunteers showed every tested Hide My Email address was exploitable, including an address used by the reporter. Murphy said Apple told him over the following months that it was investigating and, at one point, that it had fixed the issue. Murphy later found the flaw still worked, according to 404 Media.

404 Media initially withheld technical details because Apple had not yet patched the bug. After Apple said the fix was in place, Murphy and EasyOptOuts co-founder Ben Weiner described the rough mechanism: an attacker could send a message to a Hide My Email alias and trigger a rejection as spam. In some cases, that bounce or related mail handling exposed the real destination address to the sender.

Murphy and Weiner said the leak could happen even when the rejected email was legitimate and even when the user never saw it in a spam folder. They also warned that mail transfer logs may have kept the exposed data. In their view, any real address connected to a Hide My Email alias created before July 7, 2026, may have been revealed and could remain in third-party logs.

That last part is the uncomfortable bit for users. A patch can stop new leakage, assuming Apple’s fix works as described. It cannot claw an address back from logs already generated by outside mail systems.

Apple is also facing legal fallout. PCMag reported that a class action lawsuit has been filed over the Hide My Email vulnerability. The lawsuit seeks recovery of subscription fees paid by customers for the feature and an injunction related to what the complaint calls Apple’s “deceptive conduct,” according to PCMag.

Apple has said the vulnerability is fixed. Murphy and Weiner say the remaining risk is historical exposure, especially where bounced mail and retained logs are involved.

This story draws on original reporting from 404 Media.

More Security/

view all ↗