2 min read

Apple patches Hide My Email flaw after a year

Apple has fixed a Hide My Email bug that could expose anonymous addresses, but aliases created before July 7, 2026 may still linger in third-party logs.

Image: TechRadar

Apple has fixed a Hide My Email vulnerability roughly a year after security researcher Tyler Murphy first reported it, closing a bug that could expose supposedly anonymous email aliases through bounced spam logs.

The feature, part of iCloud+, lets users generate disposable email addresses instead of sharing their real address with apps, websites, and online services. That protection mattered because companies can share or sell email data, leading to spam and unsolicited offers.

In June 2025, Murphy discovered a way to connect hidden addresses to users' real inboxes, undermining the point of the service. He disclosed the issue to Apple, which initially responded with a fix, but Murphy said the problem persisted. After extended back-and-forth with the company, he eventually went public.

Murphy now says the flaw has finally been resolved, but not without limits.

Recommended reading

Paying ransomware often brings a second demand

“We don’t know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn’t make it to your inbox, so you can’t review your spam folder to learn whether you were affected.”

Tyler Murphy

According to Murphy, Apple released a working fix on July 3, 2026, and users should update immediately. But aliases created before July 7, 2026 may still have been exposed.

“Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we’d assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs.”

Tyler Murphy

That means the patch stops new leaks, but it does not erase historical exposure if those addresses were already captured in retained mail logs. Murphy’s advice, as cited by the source, is effectively to update and consider regenerating hidden addresses to reduce the remaining risk.

Best antivirus software header
Best antivirus software header
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via TechRadar

// Keep reading