Apple Fixes Hide My Email Flaw That Exposed Users’ Real Addresses


Apple has fixed a privacy flaw in Hide My Email that could reveal the real address behind an iCloud+ email alias. The exposure occurred when certain messages were rejected and the resulting email error disclosed the address that Apple intended to conceal.

Apple told 404 Media that it deployed a patch on July 3, 2026. Independent researchers verified the known attack methods as fixed on July 7 and completed further testing before Apple confirmed broader remediation on July 14.

The server-side flaw had remained unresolved for more than a year after its initial disclosure. Although the current attack no longer works, real addresses exposed before the fix may remain stored in third-party email delivery logs.

What Apple Hide My Email does

Hide My Email lets iCloud+ subscribers generate unique addresses for websites, applications, newsletters, and email conversations. Messages sent to an alias are forwarded to an address selected by the user.

According to the Apple iCloud user guide, the service prevents users from having to share their real addresses when completing online forms or registering for services.

Users can create multiple aliases, label them for different accounts, and deactivate addresses they no longer need. Replies should appear to come from the Hide My Email alias rather than the personal forwarding address.

Hide My Email componentIntended function
Random aliasReplaces the user’s personal email address
Email forwardingSends messages from the alias to the selected inbox
Reply protectionAllows replies without revealing the personal address
Address controlsLets users label, deactivate, reactivate, or delete aliases
iCloud+ integrationCreates aliases across Safari, Mail, Settings, and supported apps

How the Hide My Email flaw exposed real addresses

EasyOptOuts co-founders Tyler Murphy and Ben Weiner discovered the problem while investigating an unusual number of rejected customer emails. Some delivery failure messages contained addresses that differed from the Hide My Email aliases used by their customers.

A customer confirmed that one of the addresses shown in the logs was the private forwarding address. The researchers reported the discovery to Apple on June 11, 2025, before developing a consistent reproduction method.

The subsequent EasyOptOuts technical report explained that an attacker could send content likely to trigger spam filters. If the message received an SMTP rejection, the returned error could include the protected email address.

  1. The sender delivered a message to an Apple-generated Hide My Email alias.
  2. Apple forwarded the message toward the user’s selected inbox.
  3. A spam filter or mail server rejected the forwarded message.
  4. The receiving system generated a non-delivery response.
  5. The error details included the user’s real forwarding address.
  6. The sender or email delivery provider could read that address in its logs.

The researchers commonly encountered SMTP 550 errors stating that the message content had been rejected as spam. Other permanent rejection messages could also reveal full addresses or identifying information about the receiving mail provider.

Rejected messages could expose users without warning

Affected messages often never reached the intended user’s inbox or spam folder. Consequently, users could not inspect their mailboxes to determine whether a sender had received an error containing their real address.

Email delivery platforms commonly retain records of successful deliveries, temporary failures, permanent bounces, and rejection reasons. Retention periods vary between companies and can range from several days to multiple years.

Addresses appeared in logs associated with forwarding destinations at Gmail, Yahoo, Outlook, Proton, and other providers during the researchers’ limited testing. The issue involved Apple’s handling of rejection information rather than a vulnerability in those email providers.

Information potentially exposedPossible privacy impact
Complete personal email addressConnects an anonymous alias with a persistent identity
Email provider domainReveals information about the user’s chosen mail service
Personal domain nameCould directly identify a person or organization
Alias-to-address relationshipAllows accounts using the alias to be correlated

Researchers reported the issue in June 2025

Murphy and Weiner submitted reproducible instructions to Apple on June 13, 2025. They also supplied message identifiers and reported another exposure involving an alias whose forwarding destination had been deleted.

Apple acknowledged that Hide My Email was not designed to permit discovery of the underlying address. The company told the researchers in March 2026 that it had fixed the problem, but their testing showed that the original attack still worked.

After additional correspondence, EasyOptOuts contacted 404 Media on June 29. The publication initially withheld the technical steps to reduce the chance of exploitation while the vulnerability remained active.

DateDevelopment
June 11, 2025EasyOptOuts discovered and reported the address exposure
June 13, 2025Researchers submitted reproducible attack instructions
July 14, 2025Apple acknowledged that it was reviewing the reports
March 3, 2026Apple said it had fixed the vulnerabilities
March 19, 2026Researchers confirmed that the original attack still worked
June 29, 2026EasyOptOuts disclosed the issue to 404 Media
July 1, 2026404 Media publicly reported the vulnerability
July 2, 2026Apple deployed an initial change addressing full-address exposure
July 3, 2026Apple’s stated patch date for the resolved issue
July 6, 2026Apple deployed another update and requested verification
July 7, 2026Researchers verified that the known attacks no longer worked
July 14, 2026Apple confirmed remediation across the reported edge cases

Limited testing produced a 100% success rate

Before the fix, Murphy said every Hide My Email address included in a limited set of volunteer tests could be exposed. That group included an alias belonging to the journalist investigating the issue.

The 404 Media investigation independently confirmed the vulnerability. However, a 100% result within a limited sample does not establish how many Hide My Email users experienced actual exposure.

The researchers said they have no evidence confirming or disproving malicious exploitation. The simple reproduction method and the routine nature of email bounces created an opportunity for both deliberate attacks and accidental disclosures.

Apple’s fix cannot erase old mail logs

The server-side update prevents known rejection messages from returning the protected address. Researchers also tested custom permanent errors, temporary bounces, and successful deliveries without finding another working leak.

However, the updated researcher disclosure warns that addresses leaked before July 7 could remain in logs controlled by senders, businesses, or email delivery providers.

Fixing the forwarding system does not remove information already recorded outside Apple’s infrastructure. Anyone controlling historical logs could potentially search old rejection messages for previously disclosed addresses.

  • Mail transfer agents may retain complete rejection responses.
  • Email marketing platforms may store delivery histories.
  • Businesses may keep logs for troubleshooting or compliance.
  • Third-party delivery providers may have separate retention policies.
  • Old backups may contain copies of earlier delivery records.

A proposed class action targets Apple’s privacy claims

Apple also faces a proposed class action filed in the US District Court for the Northern District of California. The case, Alvarez v. Apple, seeks to represent iCloud+ customers and other affected Apple users.

The class action complaint alleges violations of California’s unfair competition, false advertising, and consumer protection laws. It also includes claims involving fraud, negligent misrepresentation, breach of contract, and unjust enrichment.

The plaintiff alleges that Apple continued marketing Hide My Email after learning about the reported weakness. The complaint was filed on July 15, after researchers had verified the fix but before Apple’s public confirmation received widespread coverage.

These remain allegations, and the court has not ruled that Apple violated any law. The filing also seeks class certification, recovery of subscription costs, damages, and an order addressing the alleged conduct.

According to the filed complaint, the plaintiff argues that subscribers paid for privacy protections that Hide My Email allegedly failed to provide during the affected period.

What Hide My Email users should do now

The fix occurred on Apple’s servers, so users do not need a specific iPhone, iPad, or Mac software update to close this particular vulnerability. Creating a new alias after the verified fix should avoid exposure through the documented bounce methods.

Users cannot reliably determine from their inboxes whether the flaw previously exposed an address. Someone concerned about a sensitive alias can ask the relevant service or mail provider whether it retains rejection logs containing forwarding information.

Apple’s Hide My Email controls allow users to deactivate or delete aliases they no longer need. Users should consider replacing older aliases connected to particularly sensitive or anonymous accounts.

  • Review existing Hide My Email aliases and their associated accounts.
  • Deactivate aliases that are no longer required.
  • Create new aliases for accounts where anonymity remains important.
  • Change the registered email address on sensitive services when possible.
  • Use unique passwords and multi-factor authentication for every account.
  • Monitor the real address for unexpected phishing and password-reset messages.
  • Contact the relevant mail provider when exposure could create a personal safety risk.

Deleting an alias cannot remove an address from historical third-party logs. It can still prevent accidental future use and reduce the number of services connected to an older identifier.

FAQ

Has Apple fixed the Hide My Email vulnerability?

Yes. Apple said it deployed the fix on July 3, 2026. EasyOptOuts verified the known attack methods as fixed on July 7, and Apple confirmed broader remediation on July 14.

How did the Hide My Email flaw reveal real addresses?

Certain rejected messages generated delivery errors containing the private forwarding address behind an Apple alias. The sender or its email delivery provider could then see that address in rejection logs.

Do users need to install an Apple software update?

No specific device update is required for this flaw because Apple corrected the behavior on its email infrastructure. Users should still keep their Apple devices updated for other security fixes.

Can users check whether their real email address was exposed?

Most users cannot determine this from their inboxes because rejected messages may never have reached them. Relevant mail providers or sending platforms may hold delivery logs that show whether an address appeared.

Should users replace old Hide My Email aliases?

Replacing older aliases may help when they protect sensitive or anonymous accounts. However, deleting an alias cannot remove a real address already stored in historical third-party mail logs.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages