Apple has addressed a significant vulnerability in its Hide My Email feature, which previously exposed users’ real email addresses. The flaw was initially reported in June 2025 but remained unpatched until July 3, 2026.
Hide My Email, part of Apple’s iCloud+ subscription, allows users to generate random email aliases to protect their personal addresses when signing up for services or corresponding with third parties. This feature is designed to enhance privacy by preventing the disclosure of a user’s actual email address.
The vulnerability was discovered by Tyler Murphy, co-founder of EasyOptOuts, who reported it to Apple in June 2025. Despite acknowledging the issue and stating it was under investigation, Apple did not implement a fix until after the flaw was publicly disclosed in early July 2026.
The exploit involved sending a message to a Hide My Email alias that would be rejected as spam. This rejection caused the user’s real email address to appear in email logs, potentially exposing it to unintended parties. The extent of this exposure is unclear, as legitimate emails could also trigger the flaw, and affected users may not have been aware of the issue.
Following the public disclosure, Apple released a patch on July 3, 2026, to resolve the vulnerability. However, Murphy and his colleague Ben Weiner caution that email logs predating the fix may still contain users’ real email addresses, posing an ongoing privacy risk.
In addition to the technical concerns, Apple is facing a class-action lawsuit alleging violations of California’s false advertising law and other consumer protection statutes. The lawsuit claims that Apple knowingly offered a feature that did not function as advertised, compromising user privacy.
This incident underscores the importance of timely responses to security vulnerabilities, especially for features designed to protect user privacy. Users of Hide My Email should be aware of the potential exposure of their real email addresses prior to the July 3, 2026, patch and consider monitoring their accounts for any unusual activity.