On July 3, Apple released a patch for a critical flaw in its iCloud+ feature, Hide My Email. The issue, which allowed attackers to uncover a user's real email address through spam rejection, had been known for 15 months. According to 404 Media, the flaw was first reported to Apple in June 2025 but remained unaddressed until the outlet publicly exposed it in early July 2026.
Tyler Murphy, co-founder of EasyOptOuts and the original reporter, said Apple initially responded by saying it was investigating. In March 2026, Apple claimed the issue was fixed—but it wasn't. After months of back-and-forth, Murphy lost faith in a timely resolution and turned to 404 Media to spotlight the flaw. The outlet confirmed the patch was in place but revealed how the vulnerability had worked.
How the leak happened
The Hide My Email feature lets users sign up to websites with an alias that masks their real inbox. However, if a spam filter rejected an email sent to a Hide My Email address, the system inadvertently revealed the user's actual email in the message logs. 404 Media says this process could expose addresses even when the sender had no malicious intent.
Risk remains for older accounts
Murphy and co-founder Ben Weiner warned that even after the patch was implemented, logs created before July 7, 2026, may still hold the real email addresses they were meant to hide. “Non-malicious bounces could have revealed your hidden email, and email transfer logs are often stored for years,” they wrote. Users who created Hide My Email aliases before this date may still be at risk.
Legal fallout
Plaintiffs in a current class-action lawsuit allege Apple violated California consumer protection laws by allowing the flaw to persist for over a year. The suit claims that Hide My Email did not function as advertised, and Apple failed to disclose or fix the problem in a timely manner.

