Apple has addressed a significant security flaw in its iCloud+ ‘Hide My Email’ feature, which previously allowed unauthorized access to users’ real email addresses. This vulnerability, first reported in June 2025, has now been patched as of July 3, 2026.
‘Hide My Email’ is a privacy tool available to iCloud+ subscribers, enabling users to generate unique, random email addresses that forward messages to their personal inboxes. This feature is designed to protect users’ real email addresses when signing up for online services or newsletters.
In June 2025, security researcher Tyler Murphy discovered a flaw in the ‘Hide My Email’ service that could expose users’ actual email addresses. Despite reporting the issue to Apple at that time, the vulnerability remained unpatched for over a year. Murphy’s findings indicated that the flaw was consistently exploitable, raising concerns about user privacy and data security.
Apple has now confirmed that the issue was resolved with a patch deployed on July 3, 2026. The company stated that this update fully addresses the vulnerability, ensuring that users’ real email addresses remain concealed when using the ‘Hide My Email’ feature.
This incident underscores the importance of timely responses to security vulnerabilities, especially in features designed to enhance user privacy. While Apple has now rectified the issue, the delay highlights the need for more proactive measures in identifying and addressing potential security flaws. Users are encouraged to keep their devices updated to benefit from the latest security enhancements and to remain vigilant about the privacy tools they utilize.