Mobile menu toggle

Apple fixes Hide My Email vulnerability that exposed real addresses for a year

By

An AI-generated image of an iPhone using the Hide My Email feature used in a story about Apple fixing a security exploit.
Apple finally fixes the Hide My Email flaw that allowed others to see the real email address behind an alias.
AI image: Google Gemini/Cult of Mac

Apple finally fixed the Hide My Email vulnerability that allowed outsiders to unmask a user’s real address behind an alias. The patch went live on July 3, closing a loophole that Apple knew about for more than a year.

The fix landed only after the bug became public — and a class-action lawsuit followed close behind. But the bigger question is: Why did it take outside pressure to get Apple to fix it?

How the Hide My Email vulnerability worked

The iCloud+ feature Hide My Email works by generating random addresses that forward messages to your real inbox, meaning no one knows where mail actually lands. The idea is that you can sign up for email lists or services without revealing your real email address — a protective measure against spam and other bad behavior.

But Apple’s system broke down when something specific happened. If a message sent to a hidden alias got bounced or was flagged as spam, the rejection could leak the real email address behind it.

Unfortunately, this made it easy for the Hide My Email flaw to go unnoticed by users. A bounced email rarely shows up in your inbox. And since there was nothing obvious to spot in your spam folder, most people never noticed.

A yearlong wait for a fix

Security researcher Tyler Murphy, a co-founder of EasyOptOuts, first flagged the Hide My Email problem in June 2025. Apple said it issued a fix, but Murphy later found out the exploit still worked.

The cycle repeated for months, and Apple finally shipped a real fix only after the flaw became public knowledge.

“We don’t know how often hidden email addresses were leaked in email logs,” Murphy and his EasyOptOut co-founder Ben Weiner told 404 Media in a statement published Tuesday. “For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message.”

And even now, the risk isn’t fully gone. Any alias created before July 7, 2026, may have already leaked into third-party mail server logs that Apple can’t scrub.

Apple’s privacy promise triggers lawsuit over Hide My Email vulnerability

The fallout has already reached the legal sphere. As Cult of Mac reported earlier this month, Apple is facing a proposed class-action lawsuit over the Hide My Email flaw. The suit accuses the company of selling privacy it couldn’t deliver — with Hide My Email at its center.

The timing is notable. Apple said it will unify the domains behind Hide My Email and Sign In with Apple later this year. While that move has nothing to do with this bug, it shows how much backend work is happening around these privacy tools.

What this means for you

If you use Hide My Email heavily, there’s not much you can do today. The hole is patched, and Apple says the fix now fully resolves the problem going forward.

Still, older aliases remain a big concern. If you created one before July, it will be slightly less anonymous than it used to be, especially for senders whose emails might have bounced.

Comments

Your email address will not be published. Required fields are marked *

  • Subscribe to the Newsletter

    Our daily roundup of Apple news, reviews and how-tos. Plus the best Apple tweets, fun polls and inspiring Steve Jobs bons mots. Our readers say: "Love what you do" -- Christi Cardenas. "Absolutely love the content!" -- Harshita Arora. "Genuinely one of the highlights of my inbox" -- Lee Barnett.