Tech
Hide My Email flaw worked two weeks after Apple claimed fix
Apple says it fixed a vulnerability that could expose real addresses behind Hide My Email on or around July 3, but we reproduced the flaw two weeks after the company’s claimed repair date.
The company told 404 Media that it deployed a patch on July 3, 2026, and fully resolved the vulnerability. AppleInsider successfully reproduced the behavior on July 17.
Our test found that a sender who possessed a specific Hide My Email alias could reveal the real address behind it with much technical knowledge.
We’ve reached out to Apple about the matter. We will update when we hear back from the company on the matter.
Apple spent roughly a year responding to the flaw
The vulnerability affected iCloud Hide My Email, which creates aliases that forward messages to a user’s real inbox. Users can provide a different alias to each website or service instead of sharing a permanent email address.
EasyOptOuts co-founder Tyler Murphy began reporting Hide My Email vulnerabilities to Apple in mid-2025. 404 Media says Murphy first alerted Apple in June 2025, while EasyOptOuts’ published timeline lists a related report on July 9.
Murphy and EasyOptOuts co-founder Ben Weiner exchanged reports and test results with Apple for roughly a year. EasyOptOuts says Apple declared the vulnerabilities fixed on March 3 and June 30, but the researchers reproduced the problems after both claims.
Murphy later contacted 404 Media, which reported the flaw on July 1 without publishing instructions that could help others exploit it.
Apple told 404 Media that a patch deployed on July 3 fully resolved the vulnerability. The company hasn’t said whether July 3 marked the start or completion of the deployment, but we expect it is the former.
AppleInsider reproduced the flaw on July 17
AppleInsider tested the flaw on July 17 and confirmed that the process could reveal the real address behind a Hide My Email alias.
The process required little technical knowledge once the sender possessed a specific alias, though each address had to be targeted individually. We withheld the instructions because publishing them while the vulnerability remained reproducible would have created unnecessary risk.
The test doesn’t prove the vulnerability remained active for every user or mail provider. It does show that July 3 can’t be treated as a definitive endpoint without further explanation from Apple.
Apple hasn’t explained whether the patch was deployed in stages, when the rollout finished or why the July 17 test succeeded. Without those details, the company’s claim of a complete July 3 resolution remains difficult to reconcile with independent testing.
The vulnerability was real, but its practical risk was limited
The flaw undermined the core promise of Hide My Email. A sender who possessed an alias could potentially discover the permanent address that the service was supposed to conceal.
EasyOptOuts said every address in its limited volunteer tests was vulnerable. Murphy and Weiner also said the vulnerability had been fixed, but warned that the privacy risk may continue after the patch.
Murphy and Weiner told 404 Media that rejected messages may have exposed real addresses still retained in third-party logs. EasyOptOuts recommends treating addresses linked to aliases created before July 7 as potentially exposed.
EasyOptOuts’ warning doesn’t mean every Hide My Email user was affected. A sender first needed a specific alias, which limited the number of accounts that person could target, and there’s no public evidence of a coordinated exploitation campaign.
The vulnerability didn’t expose passwords, unlock Apple Accounts or grant access to inboxes. The demonstrated consequence was the loss of an alias’s privacy protection, which could allow a permanent address to be connected with leaked or publicly available information.
A proposed class action filed after the disclosure seeks repayment of subscription fees and other relief. The complaint doesn’t allege that the named plaintiff’s address was exposed or that anyone exploited the vulnerability against him.
Apple still needs to explain the conflicting dates
The available evidence supports calling the flaw a genuine privacy failure. It doesn’t show widespread exploitation or measurable harm to subscribers.
Apple says the vulnerability has been eliminated, and Murphy and Weiner also say the bug has been fixed. We can’t reproduce it today, after our July 17 testing.
The available evidence doesn’t show that users need to disable Hide My Email entirely. Users should nevertheless treat real addresses attached to older aliases as potentially disclosed and understand that deleting an alias won’t erase information already retained in another provider’s logs.
You must be logged in to post a comment Login