Apple has addressed a significant security flaw in its iCloud+ ‘Hide My Email’ feature, which previously allowed attackers to uncover users’ real email addresses. This vulnerability undermined the core privacy function of the service, which is designed to generate random email aliases that forward messages to a user’s primary inbox, thereby keeping the real email address concealed.
The issue was first identified by security researcher Tyler Murphy, co-founder of EasyOptOuts, who reported the flaw to Apple in June 2025. Despite acknowledging the report, Apple did not implement a fix until July 3, 2026, following increased public scrutiny. During this period, the vulnerability remained exploitable, raising concerns about user privacy and data security.
Murphy discovered that by sending emails designed to trigger spam filtering mechanisms, it was possible to reveal the recipient’s actual email address. This exploit achieved a 100% success rate across multiple tests, indicating a widespread and consistent issue within the ‘Hide My Email’ system.
Apple’s delayed response has led to a class-action lawsuit alleging deceptive marketing practices. Plaintiffs argue that Apple misrepresented the security of the ‘Hide My Email’ feature, seeking compensation for iCloud+ subscription costs and demanding corrective measures to prevent future vulnerabilities.
While Apple has now patched the flaw, security experts caution that previously exposed email addresses may still exist in third-party systems due to retained logs. Users who created email aliases before July 2026 are advised to monitor their accounts for suspicious activity and consider updating their email aliases to maintain privacy.
This incident underscores the challenges of implementing privacy-preserving technologies within complex email ecosystems. It highlights the need for continuous vigilance and prompt action in addressing security vulnerabilities to protect user data effectively.