Users who rely on the Hide My Email service — part of Apple’s iCloud+ or Apple One subscription — were at risk of having their private email addresses revealed due to a long-standing security flaw. 404 Media first highlighted the issue, prompting Apple to confirm the patch was released on July 3.
The vulnerability was initially brought to Apple’s attention in June 2025 by Tyler Murphy. Although Apple reportedly said it had fixed the problem, Murphy later confirmed the bug was still active. The flaw allowed any third party to uncover the real email behind a user’s iCloud-generated alias.
The Hide My Email tool, designed to protect privacy, is meant to generate random email addresses that forward to a user's inbox. But the exposed link between the alias and the real email undermined the feature's core purpose, drawing a potential lawsuit in the wake of the report.
Apple has not provided further technical details about the patch, but claims the issue is now resolved. For now, users are advised to monitor their accounts for any unusual activity or confirm that their aliases remain secure.

