Apple has finally fixed a critical vulnerability in its Hide My Email service, which exposed users' real email addresses for more than a year. The flaw, brought to light by 404 Media, was corrected with a patch released on July 3, 2026. The issue affected the feature built into iCloud+, which allows users to generate anonymous email addresses for sign-ups and online communications.
A vulnerability ignored for months despite reports
The flaw was first reported to Apple in June 2025 by Tyler Murphy, co-founder of EasyOptOuts. After initial acknowledgment, the company claimed to have fixed the issue in March 2026, but the fix was ineffective. Only after 404 Media published details of the bug in early July did Apple issue a definitive patch. Murphy stated he contacted the outlet because he doubted Apple would act otherwise.
Sponsored Protocol
How the attack worked and the privacy risks involved
The bug was triggered when a message sent to a Hide My Email address was rejected as spam. In that case, the recipient's real email address appeared in the sender's email logs, defeating the feature's purpose. According to Murphy and Ben Weiner, also co-founder of EasyOptOuts, many email providers automatically reject legitimate messages, making it impossible for users to know if their real address was exposed. The vulnerability allowed anyone to obtain the real email simply by sending a message and having it bounced.
Although Apple has now fixed the bug, email logs prior to July 7, 2026, may still contain exposed real addresses. Murphy and Weiner warned that users who utilized Hide My Email before that date should consider their addresses potentially compromised.
Sponsored Protocol
A lawsuit questions the service's reliability
Meanwhile, Apple has been sued over this flaw. The lawsuit, seeking class action status, alleges that Apple violated California's false advertising law and other consumer protection statutes. The complaint claims Apple knew about the malfunction of Hide My Email but continued to market it as secure.
For iCloud+ users, it is essential to update their devices to the latest iOS and macOS versions to receive the fix. Privacy risks remain high, especially for those who created anonymous addresses before July 7, 2026. For more context, read about the resolved iCloud vulnerability on MeteoraWeb. For additional information on Hide My Email, see the Wikipedia entry on iCloud+.
Source: https://www.macrumors.com/2026/07/21/apple-patches-hide-my-email-flaw