← Back
Tech

Apple Fixes 15-Month-Old Hide My Email Vulnerability

Apple patched a privacy flaw in its Hide My Email feature on July 3, over a year after it was first reported to the company.
By
Apple Fixes 15-Month-Old Hide My Email Vulnerability
Foto: MacRumors
The essentials
  • A flaw allowed spammers to see users' real email addresses by sending rejected messages.
  • The vulnerability was reported in June 2025 but not fixed until July 2026.
  • Email logs from before July 7 may still contain leaked addresses from the bug.
  • A class-action lawsuit accuses Apple of false advertising over the flaw.

On July 3, Apple released a patch for a critical flaw in its iCloud+ feature, Hide My Email. The issue, which allowed attackers to uncover a user's real email address through spam rejection, had been known for 15 months. According to 404 Media, the flaw was first reported to Apple in June 2025 but remained unaddressed until the outlet publicly exposed it in early July 2026.

Tyler Murphy, co-founder of EasyOptOuts and the original reporter, said Apple initially responded by saying it was investigating. In March 2026, Apple claimed the issue was fixed—but it wasn't. After months of back-and-forth, Murphy lost faith in a timely resolution and turned to 404 Media to spotlight the flaw. The outlet confirmed the patch was in place but revealed how the vulnerability had worked.

How the leak happened

The Hide My Email feature lets users sign up to websites with an alias that masks their real inbox. However, if a spam filter rejected an email sent to a Hide My Email address, the system inadvertently revealed the user's actual email in the message logs. 404 Media says this process could expose addresses even when the sender had no malicious intent.

Risk remains for older accounts

Murphy and co-founder Ben Weiner warned that even after the patch was implemented, logs created before July 7, 2026, may still hold the real email addresses they were meant to hide. “Non-malicious bounces could have revealed your hidden email, and email transfer logs are often stored for years,” they wrote. Users who created Hide My Email aliases before this date may still be at risk.

Plaintiffs in a current class-action lawsuit allege Apple violated California consumer protection laws by allowing the flaw to persist for over a year. The suit claims that Hide My Email did not function as advertised, and Apple failed to disclose or fix the problem in a timely manner.

Based on reporting by MacRumors, compiled by the Tradingbird newsroom. Published 22 Jul 2026, 12:13.
Topics: Security

Related

Pentagon awards $821M AI data platform contract · Tech ·

200-Megawatt Data Center Push Sparks Global Backlash · Tech ·

Cloud Threats Rose 60% in H1 2026 · Tech ·

AI Boosts Cyberattacks, Weakens Security · Tech ·

AIxBio Group Aims for Evaluation Standards in AI Bio Risks · Tech ·