Apple has patched a security flaw in its Hide My Email service that could expose users’ real email addresses, weakening one of the feature’s core privacy protections.

The issue was reported by Tyler Murphy, co-founder of EasyOptOuts, on June 13, 2025, but Apple did not fully resolve it until July 3, 2026, after earlier attempts to fix the bug in March and late June 2026 proved unsuccessful.

Hide My Email, introduced in 2021 as part of iCloud+, lets users generate random email addresses that forward messages to their personal inbox while keeping their actual email address hidden from websites and online services.

According to newly released technical details, the vulnerability could expose a user’s real email address when someone sent a message to their Hide My Email address and the email was automatically rejected as spam. In those cases, the recipient’s real email address could appear in email transfer logs, potentially revealing the identity behind the anonymous address.

Researchers said they do not know how frequently the leak occurred. Because many email providers automatically reject suspected spam before it reaches a user’s inbox, affected users would likely not have indicated that their real email address had been exposed.

Although Apple has now fixed the flaw, researchers warn that email addresses associated with Hide My Email aliases created before July 7, 2026, may still have been recorded in mail server logs if rejected messages triggered the vulnerability before the patch was deployed.

READ
Apple Removes AI Nudify Apps From App Store

The disclosure comes as Apple faces a class-action lawsuit alleging that the company misled customers about the privacy protections offered by Hide My Email while charging for the feature through iCloud+. The lawsuit claims Apple knew about the vulnerability for more than a year but neither warned customers nor suspended the service while working on a fix.


Buy ExpressVPN with PayPal or Credit Card

Users do not need to take any action to receive the patch, as Apple has already addressed the issue on its servers. However, anyone who created Hide My Email aliases before the fix should be aware that their real email address may have been exposed if malicious or legitimate emails were rejected during that period.

Advertisement