Apple Patches Hide My Email Flaw More Than a Year After It Was Reported - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Apple Patches Hide My Email Flaw More Than a Year After It Was Reported

Apple addressed a vulnerability in Hide My Email that exposed a user's real email address, reports 404 Media. Apple told the site the issue was fully fixed in a patch released on July 3.

General macOS Mail Feature
The Hide My Email vulnerability was brought to Apple's attention in June 2025, but the company did not fix it until 404 Media publicized the bug in early July.

EasyOptOuts co-founder Tyler Murphy, who first reported the flaw to Apple, said he was told it was under investigation. Apple told him the vulnerability was fixed in March 2026, but it had not been. In the following months, Apple said it was again looking into the problem, but Murphy was unconvinced Apple would actually address it, so he contacted 404 Media to make it public.

404 Media confirmed the vulnerability has been patched, and has now shared details on how it worked, since it can no longer be exploited. Hide My Email is a paid iCloud+ feature that lets users create an anonymous email address for website sign-ups and email correspondence.

Sending a targeted Hide My Email user a message that got rejected as spam caused the person's real email address to appear in email logs.

"We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can't review your spam folder to learn whether you were affected," Murphy and EasyOptOuts co-founder Ben Weiner said in a new statement.

"The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. However, we don't think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs," they added.

While the bug has now been addressed, email logs that pre-date the fix could still expose user email addresses.

Apple has been sued over the Hide My Email flaw, and the plaintiffs are seeking class action status. The lawsuit says Apple violated California's false advertising law and other consumer protection statutes because Apple knew Hide My Email did not work as advertised.

Popular Stories

apple lock security bug vulnerability fix privacy

Update Now: iOS 26.6 and macOS Tahoe 26.6 Patch Hundreds of Security Flaws

Monday July 27, 2026 11:55 am PDT by
Apple today released iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6, all of which have a long list of security fixes. iOS 26.6 and iPadOS 26.6 address almost 90 security vulnerabilities affecting everything from the App Store to the Neural Engine. Multiple kernel and WebKit vulnerabilities were fixed, along with problems affecting Wi-Fi, Siri, and the iPhone's image processing. Details on...
Apple Event Logo

Apple Working on All-New Operating System

Wednesday July 29, 2026 11:39 am PDT by
Apple is developing an all-new operating system that is essentially a mix of tvOS, watchOS, and iOS, according to Bloomberg's Mark Gurman. In a report this week, he said the operating system will feature a grid of icons, widgets, and apps, along with customizable clock faces. The new software platform is intended for Apple's long-rumored smart home hub. With built-in facial recognition,...
imac video apple feature

Apple Made Its Second-Biggest Acquisition Ever This Year

Wednesday July 29, 2026 12:03 pm PDT by
Apple this year acquired Israeli startup Q.ai for close to $2 billion, according to the Financial Times. That would make this Apple's second-biggest acquisition ever, after it paid $3 billion for the popular headphone maker Beats in 2014. This is also the largest known Apple acquisition since the company purchased Intel's smartphone modem business and patents for $1 billion in 2019. Q.ai...

Top Rated Comments

turbineseaplane Avatar
1 week ago
This was swiftly taken care of in only a year!

Kudos Apple!


Apple told him the vulnerability was fixed in March 2026, but it had not been.
Oh...
Ok, less Kudos.
Score: 31 Votes (Like | Disagree)
ikramerica Avatar
1 week ago
Wow. That is a STUPID flaw to begin with. Lazy on Apple’s part.
Score: 30 Votes (Like | Disagree)
awshucks Avatar
1 week ago
This along with needing publicity to remove fake apps from the App Store is very concerning.
Score: 25 Votes (Like | Disagree)
turbineseaplane Avatar
1 week ago

This along with needing publicity to remove fake apps from the App Store is very concerning.
You don't appreciate the meticulous manicuring done inside the tender walled garden?

Apple just cares about our $afety!

I'm told that if we don't like it we are supposed to leave and if we don't like the one other option (Android) we are supposed to "start our own phone company and do it better than Apple ... if we even can!"
Score: 24 Votes (Like | Disagree)
1 week ago
Bean counters do not belong at the head of companies like Apple.

That’s all.
Score: 23 Votes (Like | Disagree)
963852741 Avatar
1 week ago
If not for bad publicity...
Score: 22 Votes (Like | Disagree)

🔗 Related Apple News & Rumors

Stay updated with the latest Apple ecosystem news and verified rumors