Apple has fixed a privacy vulnerability in its Hide My Email service that could expose users' actual email addresses, potentially defeating one of the feature's primary privacy protections.
The issue was reportedly resolved on July 3, 2026, more than a year after it was initially disclosed to Apple by Tyler Murphy, co-founder of privacy-focused service EasyOptOuts.
Introduced in 2021 as part of the iCloud+ subscription offering, Hide My Email allows users to generate random, disposable email aliases that forward messages to their personal inboxes. The feature is designed to help users protect their identities online, reduce unwanted spam, and prevent websites and services from accessing their real email addresses.
However, researchers discovered a flaw that could expose the real email address associated with a Hide My Email alias under specific circumstances.
How the Vulnerability Worked
According to recently published technical details, the issue occurred when an email sent to a Hide My Email address was automatically rejected as spam. In certain situations, the recipient's actual email address could inadvertently appear in mail transfer logs generated during the message handling process.
The vulnerability was first reported to Apple on June 13, 2025. Although Apple attempted to address the issue earlier in March 2026 and again on June 30, 2026, those efforts reportedly failed to fully eliminate the problem before a successful fix was finally deployed in July.
Researchers initially withheld detailed information to prevent abuse while remediation efforts were underway. Now that a fix has been released, additional technical information has become public.
Potential Privacy Impact
The concern surrounding the flaw stems from the possibility that users' real email addresses could be exposed without their knowledge.
According to EasyOptOuts researchers, the leakage could occur simply because an email was automatically classified as spam and rejected by the receiving system. In many cases, affected users would never see the message because it would not reach their inbox or spam folder.
As a result, individuals may have had no practical way of knowing whether their hidden email address had been exposed through backend mail logs.
While Apple has now addressed the vulnerability, researchers caution that email addresses associated with Hide My Email aliases created before July 7, 2026, may already have been recorded in mail transfer logs if affected messages were previously bounced or rejected.
Legal Challenges for Apple
The disclosure arrives as Apple faces a proposed class-action lawsuit alleging that the company misrepresented the privacy capabilities of Hide My Email while charging customers for the service.
The lawsuit argues that Apple marketed Hide My Email as a premium privacy feature but failed to adequately protect the anonymity it promised. Plaintiffs further contend that Apple was aware of the issue for an extended period and did not promptly notify users or suspend the affected functionality.
The complaint alleges that despite knowing about the vulnerability for more than a year, Apple continued promoting the service's privacy benefits without warning customers about the potential exposure risk.
What Users Should Know
Although the vulnerability has now been patched, affected users should be aware that:
- The issue has been resolved by Apple.
- The flaw could have exposed real email addresses through mail server logs.
- Users would likely have had no visible indication that exposure occurred.
- Aliases created before the July 2026 fix may have been affected if rejection events occurred while the vulnerability existed.
The incident serves as a reminder that even privacy-focused services can contain implementation flaws that undermine their intended protections, highlighting the importance of continuous security testing and timely vulnerability remediation.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
