• 2 min read
Apple fixes Hide My Email leak after 13-month delay
Apple says it patched a Hide My Email flaw on July 3 after a report first filed in June 2025. The bug could expose users' real email addresses in mail logs.

Image: MacRumors
Apple says it has fully fixed a Hide My Email vulnerability that could expose a user’s real email address, but only after the issue sat unresolved for more than a year. According to 404 Media, Apple released the patch on July 3, after the outlet raised questions about the bug in early July.
The flaw was first reported to Apple in June 2025 by Tyler Murphy, co-founder of EasyOptOuts. Murphy said Apple told him the issue was under investigation. Apple later said the vulnerability had been fixed in March 2026, but Murphy found that it had not. After more back-and-forth, he contacted 404 Media, which then confirmed the bug has now been patched and published details because it can no longer be exploited.
Hide My Email, a paid iCloud+ feature, lets users generate anonymous addresses for sign-ups and correspondence. In this case, sending a message to a targeted Hide My Email user that was rejected as spam could cause the recipient’s real email address to appear in email logs.

Recommended reading
Google Indexed DeepSeek Chats Shared by Users
“We don’t know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn’t make it to your inbox, so you can’t review your spam folder to learn whether you were affected.”
Murphy and fellow EasyOptOuts co-founder Ben Weiner said the patch does not erase the remaining risk from older records.
“The bug that caused Apple’s Hide My Email to leak hidden email addresses to senders has been fixed. However, we don’t think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we’d assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs.”
Apple is also facing a lawsuit over the flaw. The plaintiffs are seeking class action status, alleging Apple violated California’s false advertising law and other consumer protection statutes by knowing Hide My Email did not work as advertised.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via MacRumors


