Apple has taken steps to rectify a vulnerability in its Hide My Email service that previously allowed users’ actual email addresses to be revealed, compromising the service’s intended privacy protection.
The issue was initially highlighted by Tyler Murphy, co-founder of EasyOptOuts, and a remediation was put into place by Apple on July 3, 2026, after more than a year since its disclosure. This flaw was publicly reported by 404 Media, revealing that Apple had struggled with earlier attempts to fix the problem.
What is Hide My Email?
Hide My Email is a feature that creates random, disposable email addresses to forward messages to a user’s private inbox, aiming to protect privacy and reduce spam. This feature is available with a paid iCloud+ subscription and was introduced by Apple in June 2021.
However, a vulnerability exposed this privacy measure by making it possible to identify the real email address behind a Hide My Email alias. The flaw was initially reported on June 13, 2025, and despite Apple’s efforts to fix it in March and again on June 30, 2026, the issue persisted until the recent patch.
Details of the Vulnerability
The core problem occurred when a message sent to a Hide My Email address was marked as spam and subsequently rejected. This action inadvertently revealed the user’s actual email address in email logs, posing a significant privacy risk.
Tyler Murphy and EasyOptOuts co-founder Ben Weiner explained that this exposure likely happened without users’ awareness, as the rejected messages did not appear in spam folders, making it challenging to assess the full impact.
Implications and Legal Action
While the bug has been addressed, there remains a possibility that email addresses linked to Hide My Email aliases created before July 7, 2026, might still be logged if non-malicious emails were bounced.
This development has led to a class action lawsuit against Apple, with claims that the company misled consumers about the privacy protections offered by Hide My Email, despite charging for the feature. The lawsuit argues that Apple failed to inform users or pause the service during this vulnerability period.
The resolution of this flaw is critical for maintaining user trust in Apple’s privacy commitments. The ongoing legal proceedings will likely explore the extent of Apple’s responsibility and the adequacy of its response to the flaw.
