Apple has released a security fix addressing a critical flaw in its iCloud+ “Hide My Email” feature that could expose users’ real email addresses, undermining the core privacy promise of the service.
The vulnerability, which reportedly remained unresolved for over a year, allowed attackers to determine a user’s actual email address from an anonymized alias generated by Apple’s Hide My Email system.
The issue came to light after independent researcher Tyler Murphy, co-founder of EasyOptOuts, discovered that the feature could be consistently bypassed under specific conditions.
Hide My Email is designed to enhance user privacy by generating randomized email aliases that forward messages to a user’s primary inbox.
These aliases typically include random words and numbers followed by the icloud.com domain, preventing third parties from identifying or correlating a user’s real email address across services and data breaches.
However, Murphy found that sending an email designed to trigger spam filtering mechanisms could inadvertently reveal the recipient’s real email address.
In such cases, email handling systems or mail transfer logs could leak underlying address information, even if the message never reached the user’s inbox.
Apple Fixes for Hide My Email Flaw
According to Murphy, testing achieved a 100% success rate in exposing real email addresses across multiple samples after he responsibly disclosed the issue to Apple in June 2025.
Despite ongoing communication, the vulnerability remained exploitable for months. Apple reportedly acknowledged the issue multiple times but failed to remediate it until recently fully.
According to 404 Media reports, Apple patched the flaw on July 3, 2026, following increased public scrutiny and confirmed that the fix resolves the vulnerability. However, security researchers caution that some risks may still persist.
Because email infrastructure often retains logs, previously exposed email addresses could still exist in third-party systems. Any alias created before early July 2026 may have already been compromised without the user’s knowledge.
The disclosure has also led to a class action lawsuit against Apple, alleging deceptive marketing of Hide My Email as a secure privacy feature. The plaintiffs are seeking compensation for iCloud+ subscription costs and corrective measures.
The incident highlights ongoing challenges in implementing privacy-preserving technologies within complex email ecosystems. Even well-designed anonymization features can fail due to interactions with legacy systems such as spam filters, bounce handling mechanisms, and logging infrastructure.
For users, the exposure risk emphasizes the importance of layered privacy strategies. While tools like Hide My Email reduce tracking and correlation risks, they should not be relied upon as a sole protection mechanism against identity exposure.
Apple has not disclosed whether it will notify affected users directly. Security experts recommend that users who created email aliases before July 2026 consider rotating sensitive accounts and monitoring for suspicious activity.
The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment

