Software & SaaS

Apple Patches Hide My Email Flaw After Report, Lawsuit Filed

Apple has addressed a significant vulnerability in its Hide My Email feature after 404 Media's reporting and amidst a class-action lawsuit. The fix was deployed on July 3.

Christopher Clark
Christopher Clark covers software & saas for Techawave.
2 min read0 views
Apple Patches Hide My Email Flaw After Report, Lawsuit Filed
Share

Apple has issued a fix for a critical vulnerability within its Hide My Email service that allowed for the potential exposure of users' real email addresses. The company confirmed on Wednesday that the patch was deployed on July 3, addressing the security flaw that had been known for over a year. This action follows extensive reporting by 404 Media and the filing of a class-action lawsuit against the tech giant.

The Hide My Email feature, a component of Apple's paid iCloud+ subscription, is designed to generate unique, anonymous email addresses for users. These addresses are intended to protect privacy by preventing the direct sharing of personal email accounts when signing up for online services or communicating with unknown parties. Typically, these generated addresses consist of two random words, a number, and the @icloud.com domain.

Tyler Murphy, co-founder of EasyOptOuts, initially discovered and reported the exploit to Apple in June 2025. Murphy's testing indicated that a significant number of Hide My Email addresses were susceptible to being compromised. "We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable," Murphy stated at the time.

Context and Implications of the Vulnerability

Despite Apple's initial assurances that the issue was being investigated and that fixes were in progress, Murphy found the vulnerability persisted. Frustrated by the lack of resolution, Murphy eventually contacted 404 Media, approximately one year after Apple was first alerted. At the time of 404 Media's initial reporting in early July 2026, specific technical details were withheld to prevent further exploitation.

The vulnerability, in simple terms, could be triggered by sending a targeted Hide My Email user a message that was automatically rejected as spam. "We don't know how often hidden email addresses were leaked in email logs," Murphy and fellow EasyOptOut co-founder Ben Weiner explained in a new statement. "For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected."

While the immediate bug has been fixed, Murphy and Weiner cautioned that the risk may not be entirely eliminated. "The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. However, we don't think the risk to Hide My Email users has been eliminated," they stated. "Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs."

The class-action lawsuit, as reported by PCMag, seeks restitution for subscription costs paid by users of the feature and an injunction against Apple for what the plaintiffs describe as "deceptive conduct." The lawsuit highlights user concerns regarding the privacy promises made by Apple and the potential real-world consequences of such data exposure.

Source404 Media
Share