Apple: Apple Fixes Hide My Email Flaw That Exposed Users’ Real Email Addresses

Apple: Apple Fixes Hide My Email Flaw That Exposed Users’ Real Email Addresses

Apple Patches Long-Standing iCloud+ Hide My Email Vulnerability

Apple has addressed a critical flaw in its iCloud+ Hide My Email feature that could expose users’ real email addresses. The patch, deployed on July 3, 2026, arrived over a year after researchers first reported the issue to Apple.

Hide My Email allows iCloud+ subscribers to generate randomized aliases (e.g., word.word123@icloud.com) to mask their primary email when signing up for services. However, the vulnerability was triggered when messages sent to these aliases were bounced as spam by the recipient’s mail provider. During the rejection process, the sender’s mail logs could reveal the user’s actual email address even if the original message was legitimate. Since bounced emails often never reached the inbox, users had no way of knowing their real address had been exposed.

Researcher Tyler Murphy, co-founder of EasyOptOuts, discovered the flaw in June 2025 after testing it with volunteers and finding that 100% of Hide My Email addresses were exploitable. Despite Apple’s repeated assurances that the issue was under investigation and resolved, Murphy found the vulnerability persisted. After growing frustrated with Apple’s response, he disclosed the findings to 404 Media in 2026.

Even after the July 3 patch, independent testing by AppleInsider suggested the unmasking technique still worked with "moderate technical expertise," raising doubts about the fix’s completeness. Apple later confirmed to 404 Media that the issue was fully resolved.

However, researchers warn that historical exposure remains a risk, as mail transfer logs often retained by providers for extended periods may still contain users’ real addresses. Any Hide My Email alias created before July 7, 2026, should be considered potentially compromised.

The disclosure has also sparked a proposed class-action lawsuit against Apple, accusing the company of misrepresenting Hide My Email as a privacy protection while charging for iCloud+ subscriptions despite knowing about the flaw for over a year. The complaint seeks reimbursement of subscription fees and an injunction against Apple’s alleged "deceptive conduct."

Source: https://cyberpress.org/apple-fixes-hide-my-email-flaw/

Apple cybersecurity rating report: https://www.rankiteo.com/company/apple

"id": "APP1784730263",
"linkid": "apple",
"type": "Vulnerability",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'iCloud+ subscribers using Hide '
                                              'My Email',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Apple',
                        'size': 'Large',
                        'type': 'Corporation'}],
 'attack_vector': 'Email Bounce Logs',
 'customer_advisories': 'iCloud+ subscribers using Hide My Email should be '
                        'aware of potential historical exposure of their real '
                        'email addresses.',
 'data_breach': {'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'Personally Identifiable Information '
                                        '(PII)',
                 'type_of_data_compromised': 'Email addresses'},
 'date_detected': '2025-06-01',
 'date_publicly_disclosed': '2026-07-03',
 'date_resolved': '2026-07-03',
 'description': 'Apple has addressed a critical flaw in its iCloud+ Hide My '
                'Email feature that could expose users’ real email addresses. '
                'The vulnerability was triggered when messages sent to '
                "randomized aliases were bounced as spam, revealing the user's "
                'actual email address in mail logs. The issue persisted for '
                'over a year before being patched.',
 'impact': {'brand_reputation_impact': 'Yes',
            'data_compromised': "Users' real email addresses",
            'identity_theft_risk': 'Potential (historical exposure)',
            'legal_liabilities': 'Proposed class-action lawsuit',
            'systems_affected': 'iCloud+ Hide My Email feature'},
 'investigation_status': 'Resolved',
 'lessons_learned': 'Importance of timely patching and transparency in '
                    'vulnerability disclosure; risks of historical data '
                    'exposure in mail logs.',
 'post_incident_analysis': {'corrective_actions': 'Patch deployed to fix the '
                                                  'vulnerability; improved '
                                                  'communication with '
                                                  'researchers.',
                            'root_causes': 'Flaw in Hide My Email feature '
                                           'allowing real email addresses to '
                                           'be exposed via bounced email '
                                           'logs.'},
 'recommendations': 'Users should consider regenerating Hide My Email aliases '
                    'created before July 7, 2026. Companies should improve '
                    'vulnerability response times and communication with '
                    'researchers.',
 'references': [{'source': '404 Media'},
                {'source': 'AppleInsider'},
                {'source': 'Tyler Murphy (EasyOptOuts)'}],
 'regulatory_compliance': {'legal_actions': 'Proposed class-action lawsuit'},
 'response': {'communication_strategy': 'Public disclosure via 404 Media and '
                                        'AppleInsider',
              'containment_measures': 'Patch deployed to fix the vulnerability',
              'remediation_measures': 'Patch for Hide My Email feature'},
 'stakeholder_advisories': 'Users advised to regenerate Hide My Email aliases '
                           'created before July 7, 2026.',
 'title': 'Apple Patches Long-Standing iCloud+ Hide My Email Vulnerability',
 'type': 'Data Exposure',
 'vulnerability_exploited': 'iCloud+ Hide My Email feature flaw'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.