Apple has announced the fix of a critical vulnerability in its iCloud+ service that allowed anyone to access users' real email addresses despite the use of the Hide My Email feature. The bug, first reported in June 2025 by researcher Tyler Murphy, was patched on July 3, 2026. The news was confirmed by 404 Media, which initially reported the flaw.
The vulnerability involved the email forwarding system of Hide My Email, an iCloud+ feature that generates random, unique email addresses to protect user privacy. According to reports, an attacker could trace back to the real address by exploiting a defect in the forwarding logic. Such exposure could have serious consequences, enabling targeted phishing or spam campaigns.
The July 2026 patch resolves the issue after a failed initial attempt
Apple had previously tried to fix the flaw, but the initial fix proved ineffective. With the July 3 patch, the company states it has fully resolved the issue. Tyler Murphy, after verifying the correction, confirmed that the vulnerability is no longer exploitable. This incident highlights the importance of continuous security monitoring even for trusted services.
Sponsored Protocol
Hide My Email is particularly useful for those who want to avoid sharing their primary email address on websites, newsletters, or online forms. However, this recent flaw demonstrates that no system is immune to errors. Security experts recommend using unique passwords and, where possible, two-factor authentication.
Privacy implications and comparison with other digital threats
This vulnerability fits into a context of growing online privacy attacks. Deepfake fraud losses reach $3.7 billion with social media as the top vector, showing how exposure of personal data paves the way for increasingly sophisticated scams. Although the iCloud+ vulnerability has been fixed, it remains crucial for users to adopt good security practices, such as periodically reviewing their Apple account privacy settings.
Sponsored Protocol
Apple stated that the patch was applied automatically on the servers, requiring no action from users. For more information, you can consult the official support page on iCloud.
In conclusion, the timely correction of this flaw demonstrates Apple's commitment to protecting user data, but also the need for continuous vigilance. If you regularly use Hide My Email, check your settings and stay updated on security news.
Source: https://9to5mac.com/2026/07/21/apple-fixes-icloud-vulnerability-that-exposed-hidden-user-emails