Home Risk & Resilience Apple Fixes Hide My Email Bug That Exposed Real Addresses In Mail Logs

Apple Fixes Hide My Email Bug That Exposed Real Addresses In Mail Logs

0
Apple Fixes Hide My Email Bug That Exposed Real Addresses In Mail Logs

Apple has fixed a security flaw affecting its Hide My Email service that could expose users’ real email addresses, reducing the privacy protections offered by the feature. According to reports, Apple deployed a fix on July 3, 2026, more than a year after the issue was responsibly disclosed by Tyler Murphy, co founder of EasyOptOuts. Hide My Email is a privacy feature available through an iCloud Plus subscription that creates unique random email addresses which automatically forward messages to a user’s primary inbox. The service was introduced by Apple in June 2021 to help users protect their personal email addresses, reduce unwanted spam, and improve online privacy by allowing disposable email aliases to be used when signing up for websites and online services.

The vulnerability allowed a user’s actual email address to be revealed under specific conditions, undermining the core privacy function of Hide My Email. Researchers reported the issue to Apple on June 13, 2025, after discovering that sending an email to a Hide My Email address which was later rejected as spam could result in the recipient’s real email address appearing within mail transfer logs. Apple attempted to resolve the issue during March 2026 and again on June 30, 2026, but those earlier fixes did not completely eliminate the vulnerability. To reduce the possibility of exploitation, technical details about the flaw were initially withheld until Apple released a successful update. According to Tyler Murphy and EasyOptOuts co founder Ben Weiner, it remains unclear how frequently users’ real email addresses may have been exposed because many major email providers automatically rejected certain messages as spam before they reached recipients’ inboxes. As a result, affected users may never have been aware that the information had been recorded within email logs.

Although Apple has now addressed the vulnerability, researchers noted that email aliases created before July 7, 2026, may still have been exposed if rejected messages caused the associated email addresses to be recorded in mail transfer logs before the fix was implemented. While the issue did not expose email addresses through ordinary inbox activity, the possibility that legitimate messages rejected by spam filters could reveal users’ personal addresses raised concerns about the privacy guarantees provided by the service. Hide My Email was specifically designed to prevent websites, online services, and third parties from learning a user’s actual email address by routing communications through randomly generated aliases. The vulnerability therefore affected one of the primary security objectives of the feature by creating a situation where the hidden address could become visible under particular circumstances outside the user’s control.

The disclosure comes as Apple faces a class action lawsuit related to the Hide My Email service. According to the legal complaint, Apple is accused of misleading customers regarding the privacy protections provided by the feature while continuing to offer it as part of the paid iCloud Plus subscription. The complaint further alleges that Apple was aware of the vulnerability for more than a year before releasing a complete fix and did not suspend the service, notify customers about the issue, or revise its privacy related statements during that period. Apple has now implemented a fix intended to prevent future exposure of users’ email addresses, although researchers noted that historical mail transfer logs created before the update may still contain previously exposed information generated before the vulnerability was fully resolved.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.