Apple addressed a vulnerability in Hide My Email that exposed a user's real email address, reports .Apple told the site the issue was fully fixed in a patch released on July 3.The Hide My Email vulnerability was brought to Apple's attention in June 2025, but the company did not fix it until publicized the bug in early July.
EasyOptOuts co-founder Tyler Murphy, who first reported the flaw to Apple, said he was told it was under investigation.Apple told him the vulnerability was fixed in March 2026, but it had not been.In the following months, Apple said it was again looking into the problem, but Murphy was unconvinced Apple would actually address it, so he contacted to make it public.
confirmed the vulnerability has been patched, and has now shared details on how it worked, since it can no longer be exploited.Hide My Email is a paid iCloud+ feature that lets users create an anonymous email address for website sign-ups and email correspondence.Sending a targeted Hide My Email user a message that got rejected as spam caused the person's real email address to appear in email logs.
While the bug has now been addressed, email logs that pre-date the fix could still expose user email addresses.Apple has been sued over the Hide My Email flaw, and the plaintiffs are seeking class action status.The lawsuit says Apple violated California's false advertising law and other consumer protection statutes because Apple knew Hide My Email did not work as advertised.
Read More