Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Apple Resolves Hide My Email Security Flaw

Apple Resolves Hide My Email Security Flaw

Posted on July 21, 2026 By CWS

Apple has taken steps to rectify a vulnerability in its Hide My Email service that previously allowed users’ actual email addresses to be revealed, compromising the service’s intended privacy protection.

The issue was initially highlighted by Tyler Murphy, co-founder of EasyOptOuts, and a remediation was put into place by Apple on July 3, 2026, after more than a year since its disclosure. This flaw was publicly reported by 404 Media, revealing that Apple had struggled with earlier attempts to fix the problem.

What is Hide My Email?

Hide My Email is a feature that creates random, disposable email addresses to forward messages to a user’s private inbox, aiming to protect privacy and reduce spam. This feature is available with a paid iCloud+ subscription and was introduced by Apple in June 2021.

However, a vulnerability exposed this privacy measure by making it possible to identify the real email address behind a Hide My Email alias. The flaw was initially reported on June 13, 2025, and despite Apple’s efforts to fix it in March and again on June 30, 2026, the issue persisted until the recent patch.

Details of the Vulnerability

The core problem occurred when a message sent to a Hide My Email address was marked as spam and subsequently rejected. This action inadvertently revealed the user’s actual email address in email logs, posing a significant privacy risk.

Tyler Murphy and EasyOptOuts co-founder Ben Weiner explained that this exposure likely happened without users’ awareness, as the rejected messages did not appear in spam folders, making it challenging to assess the full impact.

Implications and Legal Action

While the bug has been addressed, there remains a possibility that email addresses linked to Hide My Email aliases created before July 7, 2026, might still be logged if non-malicious emails were bounced.

This development has led to a class action lawsuit against Apple, with claims that the company misled consumers about the privacy protections offered by Hide My Email, despite charging for the feature. The lawsuit argues that Apple failed to inform users or pause the service during this vulnerability period.

The resolution of this flaw is critical for maintaining user trust in Apple’s privacy commitments. The ongoing legal proceedings will likely explore the extent of Apple’s responsibility and the adequacy of its response to the flaw.

The Hacker News Tags:Apple, class action, cloud security, email security, Hide My Email, iCloud, Privacy, security flaw, tech news, Vulnerability

Post navigation

Previous Post: Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
Next Post: Fake Game Downloads Deliver Multi-Stage Infostealers

Related Posts

Why Runtime Visibility Must Take Center Stage Why Runtime Visibility Must Take Center Stage The Hacker News
Keycloak Password Vulnerability: Critical Update Released Keycloak Password Vulnerability: Critical Update Released The Hacker News
Security Challenges Posed by AI-Driven Apps Exposed Security Challenges Posed by AI-Driven Apps Exposed The Hacker News
Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware The Hacker News
Identity Posture: A Key Factor in Cyber Insurance 2026 Identity Posture: A Key Factor in Cyber Insurance 2026 The Hacker News
Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark