2 min read

Apple patches Hide My Email flaw after report

Apple says it fixed a Hide My Email bug on July 3 after 404 Media reported it. Researchers say addresses created before July 7, 2026, may still have leaked.

Image: Chris Nagahama

Apple says it has fixed a Hide My Email vulnerability that could let attackers uncover a user’s real email address, despite the feature being designed to keep it private. The company told 404 Media on Wednesday that it deployed a patch on July 3 and that the issue is now fully resolved.

The report says Apple had known about the bug for more than a year and only fixed it after 404 Media wrote about it at the start of July. The disclosure also comes after a class action lawsuit was filed against Apple over the flaw.

Hide My Email, part of the paid iCloud+ subscription, lets users generate anonymous addresses for signing up to websites, services, and emails. Those addresses typically use two random words, a number, and the @icloud.com domain.

The issue was discovered by Tyler Murphy, co-founder of EasyOptOuts, who said he was able to find the real email addresses behind Hide My Email aliases. Murphy first reported the bug to Apple in June 2025. According to 404 Media, Apple repeatedly said it was investigating or had fixed the problem, but Murphy found it remained exploitable.

Recommended reading

DeepSeek chats surfaced in Google search results

At the time, Murphy said:

“We don’t know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.”

Tyler Murphy, co-founder of EasyOptOuts

404 Media says it initially withheld technical details because Apple had not yet patched the bug. Now that the company says the flaw is fixed, the publication reports that, in simple terms, the exploit involved sending a message to a target Hide My Email address that would be rejected as spam.

In a new statement, Murphy and Ben Weiner, another EasyOptOut co-founder, said the risk may not be fully gone because previously exposed addresses could still exist in mail transfer logs.

“The bug that caused Apple’s Hide My Email to leak hidden email addresses to senders has been fixed. However, we don’t think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we’d assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs.”

Tyler Murphy and Ben Weiner, EasyOptOuts

According to PCMag, the lawsuit seeks full recovery of the subscription fees customers paid for the feature, as well as an injunction over Apple’s alleged “deceptive conduct.”

Joseph Cox
Joseph Cox
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via Hacker News

// Keep reading