Tech

Fake Hide My Email header can expose your Apple Account

Published

on

A forged Hide My Email header can make Mac Mail expose a user’s Apple Account address, extending the privacy risk beyond people who use Apple’s alias service.

Developer Jeff Johnson disclosed the Mac Mail privacy flaw on July 19. His testing showed that a specially crafted message could make Mail display a misleading sender identity while a reply went out from the email address tied to his Apple Account.

The behavior didn’t require Johnson to use Hide My Email or maintain an iCloud.com mailbox. He also found that the malicious message could arrive through an unrelated personal or business account before Mail exposed the Apple Account address in a reply.

Johnson said he doesn’t know whether the finding is technically related to an earlier flaw that could reveal the address behind a Hide My Email alias. His report documents a separate technique and doesn’t establish that both issues share the same underlying cause.

Advertisement

Johnson used the curl command-line tool to send himself an email containing an arbitrary X-Icloud-Hme header. Mail doesn’t give users direct control over arbitrary outgoing headers, while curl allowed him to choose the values placed inside it.

By controlling those values, Johnson could make Mail show selected addresses in the reply window. The app also displayed “Hide My Email” in the From field and added a notice saying the message had been forwarded through the service.

The result suggests Mail accepted information supplied by the sender without first establishing that Apple’s Hide My Email service had generated it. Johnson demonstrated the visible behavior, but his report doesn’t identify the app’s internal validation process.

A crafted X-Icloud-Hme header was sufficient to trigger the Mac Mail bug in Johnson’s testing. Image credit: Jeff Johnson

The problem goes beyond a misleading label because users rely on the From field to confirm which account will send a message. Mail reportedly showed one identity while sending the reply from another, giving Johnson no accurate warning that his Apple Account address would be exposed.

The reported flaw reaches beyond Hide My Email users

Johnson said he doesn’t use Hide My Email and doesn’t have an iCloud.com email account. That makes the reported issue broader than a flaw limited to people actively using Apple’s alias service.

Advertisement

A crafted message can also arrive through a separate email account, yet Johnson said Mail may still send the reply from the address tied to the recipient’s Apple Account. The distinction matters for people who keep personal, business and Apple Account identities inside the same Mail app.

Apple Mail can manage multiple accounts from different providers, and users reasonably expect those identities to remain separate. Johnson’s test shows that the compose window may not always reflect the address that Mail will actually transmit.

Johnson documented a technique he reproduced in his own testing, but the report doesn’t establish which macOS versions are affected. It also doesn’t show whether the same behavior works in Mail on iPhone or iPad, and it offers no evidence that anyone has used the technique in an attack.

The only other warning was a notice above the message saying it had been forwarded through Hide My Email. Image credit: Jeff Johnson

Crafted email headers have caused problems for Apple Mail before. In 2022, a specially formatted From field could prevent some iOS 16 users from opening Mail, although that issue caused a crash rather than exposing an email address.

The new finding also arrives while Apple faces legal scrutiny over the earlier Hide My Email disclosure. A proposed class action lawsuit filed July 15, accuses the company of misleading customers about the feature, although the complaint doesn’t allege that attackers exposed the plaintiff’s address or exploited the flaw.

Advertisement

How to protect yourself from the Mac Mail disclosure flaw

Mac Mail users should stop before sending when a reply window unexpectedly labels the From address as “Hide My Email,” particularly when the original message wasn’t sent to an alias. In Johnson’s test, the disclosure occurred only after he sent the reply.

Users can inspect a received message’s complete headers by opening the View menu, selecting Message and choosing All Headers. Johnson noted that the command can also be added to the message window’s toolbar.

The presence of an X-Icloud-Hme header doesn’t establish who added it or why. An unexpected Hide My Email label combined with unusual From or To fields should still be treated as a warning.

MacGeneration independently reproduced the Mail bug and confirmed that it can expose an Apple Account address even when the user doesn’t use iCloud for email. The publication’s testing supports Johnson’s findings, though the affected Mail app versions remain unclear.

Advertisement

Users who need to respond should create a new message and confirm the From address before sending instead of replying directly to the suspicious email. Creating a separate message won’t fix the underlying Mail bug, but it avoids the reply behavior Johnson documented.

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version