HomeAppsApple Patches Hide My Email Flaw More Than a Year After It...

Apple Patches Hide My Email Flaw More Than a Year After It Was Reported

Apple Patches Vulnerability in Hide My Email Feature

Apple recently addressed a significant vulnerability in its Hide My Email feature that exposed users’ real email addresses. This issue, reported by 404 Media, was resolved with a patch released on July 3. The flaw had been a point of concern for users relying on Apple’s iCloud+ service, which offers the ability to create anonymous email addresses for privacy-conscious communication.

The Discovery and Response

The vulnerability was first brought to Apple’s attention in June 2025 by Tyler Murphy, co-founder of EasyOptOuts. Murphy reported the flaw and was initially informed that it was under investigation. Apple later claimed the issue had been fixed by March 2026; however, the problem persisted until it was publicized by 404 Media in early July.

Once the issue was made public, Apple moved swiftly to patch the vulnerability. According to 404 Media, the flaw has now been resolved, and they have shared insights into how it functioned since it can no longer be exploited.

Understanding the Vulnerability

Hide My Email, a feature of iCloud+, allows users to create temporary, anonymous email addresses for online activities. The vulnerability involved sending a message to a Hide My Email user that was rejected as spam. This rejection caused the user’s real email address to appear in email logs, potentially compromising their privacy.

Murphy and EasyOptOuts co-founder Ben Weiner explain, “We don’t know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn’t make it to your inbox, so you can’t review your spam folder to learn whether you were affected.”

Implications and Legal Action

Although the vulnerability has been fixed, concerns remain about email logs that pre-date the patch, which might still reveal users’ real email addresses. Apple is reportedly facing a lawsuit over this flaw, with plaintiffs seeking class action status, alleging violations of California’s false advertising law and other consumer protection statutes.

The lawsuit claims Apple was aware that Hide My Email did not function as advertised, putting users’ privacy at risk. As the situation unfolds, it highlights the importance of ongoing vigilance and prompt resolution of security vulnerabilities.

For more information, you can read the original report here.

“`

Must Read
Related News

LEAVE A REPLY

Please enter your comment!
Please enter your name here