Friday, September 11, 2026

Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses

Apple has addressed a year-old vulnerability in its “Hide My Email” privacy feature, which could expose users’ real email addresses. This incident has already led to a class action lawsuit and increased scrutiny of Apple’s privacy claims.

Hide My Email, part of the paid iCloud+ subscription, allows users to generate random alias addresses that forward emails to their real inboxes.

This feature is designed to decouple online identities from primary email accounts. Security researcher Tyler Murphy, co-founder of EasyOptOuts, discovered that these aliases could be reliably linked back to the real email addresses, undermining the anonymity that the feature was intended to provide.

In limited volunteer testing, Murphy reported that 100% of sampled Hide My Email aliases were exploitable, indicating that the issue was systemic rather than an isolated case.

Hide My Email Vulnerability Exposed

According to Murphy and EasyOptOuts co-founder Ben Weiner, exploiting this vulnerability did not require elevated privileges or insider access; it only needed carefully crafted email traffic.

Specifically, if a message sent to a Hide My Email alias was rejected as spam, the real, hidden address could appear in mail transfer logs kept by major email providers.

Since these bounce events usually happen before messages reach the users’ inboxes, affected Hide My Email customers had no reliable way to check spam folders or mail logs to see if their real addresses had been exposed.

Murphy first reported the flaw to Apple in June 2025. The company acknowledged investigating the issue multiple times and even claimed to have fixed it, but the vulnerability persisted.

Apple ultimately deployed a server-side patch on July 3, 2026, after media coverage highlighted the ongoing risk. The company now asserts that the bug has been fully resolved.

However, EasyOptOuts advises users to assume that any Hide My Email alias created before July 7, 2026, may have had its corresponding real email address logged by third-party mail providers and might still exist in those logs.

Apple is now facing a proposed class action lawsuit in California, alleging false advertising and deceptive conduct. The lawsuit claims that the company charged for iCloud+ while promoting Hide My Email as a strong privacy control, despite knowing about the vulnerability for over a year.

The complaint seeks reimbursement of subscription fees and an injunction requiring Apple either to deliver the promised privacy protections or to disclose the feature’s technical limitations clearly, as reported by 404 Media.

For security-conscious users, this case highlights the necessity of treating vendor “privacy” branding as marketing claims that must be verified. It also underscores the need to assume that email aliases and forwarding services can leak metadata or identifiers through infrastructure-layer logging, even when application-layer behavior appears private.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News