
FaceTime Like a Pro
Get our exclusive Ultimate FaceTime Guide 📚 — absolutely FREE when you sign up for our newsletter below.

FaceTime Like a Pro
Get our exclusive Ultimate FaceTime Guide 📚 — absolutely FREE when you sign up for our newsletter below.
Apple has patched a Hide My Email vulnerability that could expose users' real email addresses, more than a year after the issue was first reported by security researchers.
Apple has fixed a vulnerability in Hide My Email that could expose a user’s real email address instead of keeping it anonymous. The company confirmed to 404 Media that the issue was fully patched in an update released on July 3.
The vulnerability affected Hide My Email, an iCloud+ feature that allows users to sign up for apps and websites without revealing their personal email address by using randomly generated aliases.
The vulnerability was first reported to Apple in June 2025 by EasyOptOuts co-founder Tyler Murphy.
According to Murphy, Apple acknowledged the report shortly after it was submitted and later informed him that the issue had been fixed in March 2026. However, after testing the feature again, Murphy discovered that the vulnerability was still present.
After additional discussions with Apple failed to produce a working fix, Murphy contacted 404 Media, which published a report detailing the issue earlier this month.
Now that Apple has released a patch, 404 Media has explained how the vulnerability worked.
If someone sent an email to a targeted Hide My Email alias and that message was automatically rejected as spam, the recipient’s real email address could appear in email server logs instead of remaining hidden behind the generated alias.
With the bug now fixed, 404 Media has explained how it worked. If someone sent an email to a targeted Hide My Email address and that message was automatically rejected as spam, the recipient’s real email address could appear in email server logs instead of remaining hidden.
According to Murphy and EasyOptOuts co-founder Ben Weiner, many users may never know whether they were affected because the rejected emails never reached their inbox or spam folder. Since those messages were filtered before delivery, users had no practical way to determine whether their real email address had been exposed.
“The bug has been fixed. However, we don’t think the risk to Hide My Email users has been eliminated.”
Murphy and Weiner argue that any Hide My Email alias created before July 7, 2026, should be considered potentially exposed, as mail transfer logs are often retained for extended periods.
In other words, while Apple’s update prevents the vulnerability from occurring in the future, any real email addresses already recorded in historical mail logs cannot be removed retroactively.
The security flaw has also led to a proposed class-action lawsuit against Apple.
The plaintiffs allege that Apple violated California’s false advertising and consumer protection laws by continuing to market Hide My Email as a privacy feature despite allegedly being aware of the vulnerability before it was fully resolved.
The lawsuit is seeking class-action status and is expected to focus on whether Apple adequately protected users while the flaw remained unpatched.
Although Apple has now fixed the vulnerability, the legal case could determine whether the company responded appropriately after learning about the issue and whether users were sufficiently informed while the bug remained unresolved.
Does this vulnerability affect your confidence in Apple’s Hide My Email feature? Let us know in the comments below.