Apple says it has closed the Hide My Email vulnerability, but a test reproduces it again
Apple announced that it has fixed the vulnerability in Hide My Email that allowed a sender to trace back to the real email address hidden behind an alias. The company stated that it rolled out the patch on July 3 and considers the problem fully resolved. The statement was shared with 404 Media, which had raised the issue in recent weeks. However, the solution does not seem to be particularly effective, as AppleInsider was able to reproduce the flaw on July 17, two weeks after the update was released.
The feature is part of iCloud+, Apple's paid package, and was introduced in 2021 to generate random addresses that forward mail to the user's actual inbox, so users never have to communicate it to websites and services. The promise is the confidentiality of the real address, which the vulnerability fundamentally undermined.
The mechanism was as simple as it was effective: it was enough to send the target user a message to their Hide My Email alias that was rejected as spam. The rejection would expose the real address in the mail logs, which are readable by the sender. In tests conducted with a small group of volunteers, all tested addresses were found to be exposed.
A Year of Announced and Unsuccessful Fixes
Tyler Murphy, co-founder of EasyOptOuts, reported the issue to Apple in June 2025. In the following months, Cupertino declared several times that it had fixed it, only to see Murphy replicate the vulnerability each time: two announced closure dates, March 3 and June 30, 2026, were both disproved by testing. Convinced that the issue would not be resolved, the researcher turned to 404 Media, which published the news on July 1 without indicating how to exploit the flaw, in order not to offer instructions to third parties.
The July 3 patch comes after over a year and only following media coverage. However, AppleInsider reported that it managed to reproduce the behavior on July 17, without any particular technical expertise once a specific alias was obtained, while clarifying that it could not replicate it at the time of publication. It is currently unclear if the flaw remains active for all users and all mail providers.
The Risk That the Fix Does Not Eliminate
Even assuming the flaw is closed, researchers do not consider the danger eliminated. In a note, Murphy and co-founder Ben Weiner write: "The bug that caused Apple’s Hide My Email to reveal hidden addresses to senders has been fixed. However, we do not believe that the risk to users has been eliminated. Since even legitimate emails can bounce back, exposing the hidden address, and since mail transfer logs are often retained, we assume that any hidden address linked to an alias created before July 7, 2026 may have been exposed and could still be in third-party logs."
The consequence is that deleting an alias does not clean up what has already ended up in another provider's logs. Those who created Hide My Email addresses before that date would do well to treat their real address as potentially already known. It should be noted that the flaw did not expose passwords nor provide access to inboxes: the damage was the loss of shielding, i.e., the possibility of linking a permanent address to leaked or public data. To target someone, one still needed to have their alias, which limited the number of targets, and there are no reports of coordinated exploitation campaigns.
On the judicial front, Apple must meanwhile respond to a class action lawsuit filed on July 15, accusing it of violating California's misleading advertising law and other consumer protection regulations. The plaintiffs are seeking full refunds of the subscriptions paid for the function and an injunction against the company's "deceptive conduct." According to the filing, Apple "was fully aware of the problem for over a year and did not resolve it," without ever suspending the function or notifying customers. The complaint does not claim that the plaintiff's address was actually exposed.