Apple has patched a long-standing vulnerability in its iCloud+ Hide My Email feature that allowed anyone to unmask a user’s real email address. The patch, applied on July 3, 2026, comes more than a year after researchers first alerted Apple to the issue.
Hide My Email lets iCloud+ subscribers generate anonymous, randomized email aliases (typically two words plus a number ending in @icloud.com) to sign up for services without exposing their real inbox.
The flaw was triggered when a message sent to a Hide My Email alias got bounced as spam by the recipient’s mail provider; in that rejection process, the sender’s mail logs would reveal the user’s actual underlying email address, even if the original message was completely legitimate.
Apple Fixes Hide My Email Flaw
404 Media stated that because the bounced emails often never reached the inbox, victims had no way of checking their spam folder to determine whether they had been exposed.
Tyler Murphy, co-founder of the opt-out service EasyOptOuts, first reported the issue to Apple in June 2025 after finding that 100% of Hide My Email addresses tested with volunteers were exploitable.
Over the following year, Apple repeatedly told Murphy it was investigating and had resolved the problem, only for him to find the flaw still worked; frustrated by the cycle, Murphy eventually brought the findings to 404 Media.
Even after Apple’s July 3 patch, AppleInsider independently tested the alias-unmasking technique two weeks later and reported it still functioned with a “moderate level of technical expertise,” raising questions about whether the fix was truly comprehensive. Apple has since told 404 Media the issue is now fully resolved.
Murphy and EasyOptOuts co-founder Ben Weiner have cautioned that patching the bug does not eliminate historical exposure, since mail transfer logs are frequently retained by email providers for extended periods.
They advise that any Hide My Email alias created before July 7, 2026, should be treated as potentially compromised and possibly still present in third-party logs.
The disclosure has fueled a proposed class action lawsuit against Apple, which alleges the company misrepresented Hide My Email as a genuine privacy protection while charging for iCloud+ subscriptions, despite knowing about the exploitable flaw for over a year.
The complaint seeks full reimbursement of subscription fees tied to the feature along with an injunction against what plaintiffs call Apple’s “deceptive conduct”.
Tips For Users
404media covering the incident suggests the following precautions for affected users:
- Treat any Hide My Email alias created before July 7, 2026 as potentially exposed in third-party mail logs.
- Monitor accounts tied to older aliases for unusual activity, since real addresses may have been logged even from non-malicious bounced emails.
- Consider generating new Hide My Email aliases for sensitive signups going forward, now that Apple says the underlying bug is patched.
- Stay alert for further verification reports, as independent testing found the fix’s effectiveness was initially inconsistent.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.