Apple Patches Hide My Email Flaw That Could Reveal Users’ Real Addresses
Apple has fixed a vulnerability in its Hide My Email service that could expose the personal email address associated with a privacy alias in mail-transfer logs.The issue, reported by 404 Media, was di...
Apple has fixed a vulnerability in its Hide My Email service that could expose the personal email address associated with a privacy alias in mail-transfer logs.
The issue, reported by 404 Media, was disclosed to Apple on June 13, 2025, by Tyler Murphy, co-founder of the opt-out service EasyOptOuts. Apple deployed a fix on July 3, 2026, after earlier remediation attempts in March and on June 30 were unsuccessful, according to the report.
How the exposure occurred
Hide My Email, available to iCloud+ subscribers, creates random forwarding addresses that allow users to communicate without disclosing their primary email address. Messages sent to an alias are forwarded to the user’s regular inbox.
Researchers said the flaw could be triggered when a message sent to a targeted alias was rejected as spam. Under some circumstances, the rejection process caused the recipient’s underlying email address to appear in mail logs maintained by email providers. The message did not necessarily need to reach the user’s inbox, meaning affected individuals might have had no practical way to detect the exposure by checking their mail.
Murphy and EasyOptOuts co-founder Ben Weiner told 404 Media that the number of addresses potentially recorded in logs is unknown. They also said the issue affected multiple major email providers, although the precise conditions may have varied between services.
Potential historical exposure
Although the technical issue has been addressed, addresses linked to Hide My Email aliases created before July 7, 2026, could have been recorded in mail-transfer logs when legitimate messages were rejected or bounced. Apple has not indicated how many users may have been affected.
The disclosure comes as Apple faces a proposed class-action lawsuit alleging that the company overstated Hide My Email’s privacy protections while charging for access through iCloud+. The complaint claims Apple knew about the flaw for more than a year but did not suspend the service, notify customers, or revise its privacy statements.
Users who rely on Hide My Email should continue using the service’s updated software and review account activity where possible, while recognizing that historical provider logs may not be retrievable or visible to customers.
