
Apple has fixed a vulnerability in its iCloud+ Hide My Email service that could expose users' real email addresses.
The fix comes over a year after a security researcher privately reported the issue and only weeks after 404 Media publicly disclosed it.
The company confirmed to 404 Media that it deployed a server-side fix on July 3, 2026, resolving the flaw. The disclosure follows increasing public scrutiny, including a proposed class-action lawsuit filed last week accusing Apple of misleading customers about the privacy protections offered by the paid feature.
The vulnerability was discovered by Tyler Murphy, co-founder of privacy service EasyOptOuts, who responsibly disclosed it to Apple in June 2025. Apple investigated the report over the following year, at one point stating the issue had been fixed before Murphy determined it remained exploitable. After repeated discussions failed to yield a permanent fix, Murphy contacted 404 Media, which published its initial report earlier this month while withholding technical details to prevent abuse before a patch became available.
Hide My Email is an iCloud+ feature introduced in 2021 that lets users generate random email aliases instead of sharing their real address when signing up for websites, apps, or online services. Messages sent to these aliases are automatically forwarded to the user's primary inbox, helping reduce spam and limit cross-site tracking while masking the underlying email address.
With the vulnerability now patched, the researcher disclosed how the issue worked. An attacker could trigger the exposure by sending an email that the recipient's email infrastructure automatically rejects as spam. Under those conditions, the sender could learn the user's real email address instead of only seeing the Hide My Email alias.
The researcher warned that the patch does not eliminate all risk for users whose aliases existed before the fix. They said mail transfer logs are commonly retained by email providers, meaning real email addresses that were previously exposed during rejected deliveries could remain stored in third-party systems. As a precaution, they recommend assuming any Hide My Email alias created before July 7, 2026, may have been exposed if such conditions occurred.
The fix comes days after California resident Anthony Alvarez filed a proposed class-action lawsuit alleging that Apple continued to market Hide My Email as a privacy feature despite knowing about the vulnerability for more than a year. The complaint seeks reimbursement of iCloud+ subscription fees paid for the feature and an injunction against what it describes as deceptive conduct.
Last month, Apple announced that newly generated Hide My Email aliases will move from the standard @icloud.com domain to @private.icloud.com, unifying them with Sign in with Apple's email relay infrastructure. While Apple said the change is intended to consolidate its relay services, privacy advocates noted that the dedicated domain could make anonymous relay addresses easier for websites to identify and potentially block.
Earlier this year, court documents also showed that Apple can identify the account behind a Hide My Email alias when presented with a lawful request, following the company's provision of subscriber information to the FBI during a criminal investigation. That case underscored that the feature is designed to conceal users' email addresses from third parties, not from Apple itself or law enforcement acting under valid legal process.
Users who rely on Hide My Email should ensure they are using aliases created after Apple's July fix and consider replacing older aliases used for sensitive accounts if they are concerned about prior exposure.







Leave a Reply