Home News Apple Patches Hide My Email Vulnerability a Year After First Report

Apple Patches Hide My Email Vulnerability a Year After First Report

The iCloud+ alias flaw survived two claimed fixes - until 404 Media went public

5
0
Apple iCloud+ logo artwork representing the Hide My Email vulnerability patch
Image: Apple

Apple has finally patched a Hide My Email vulnerability that undermined one of iCloud+’s core privacy promises. The working fix arrived on July 3, 2026, according to a new report from 404 Media, the outlet that first exposed the flaw and later confirmed the patch. Notably, that repair landed more than a year after a security researcher first warned Apple about the problem.

What the Hide My Email flaw exposed

Hide My Email creates random email aliases so subscribers can sign up for services without revealing their real address. Apple launched the feature in 2021 as part of its paid iCloud+ bundle. Millions of people rely on it to keep spammers and data brokers away from their primary inbox. However, the flaw flipped that shield around. An attacker only needed to send a message that a mail server rejected as spam. Under certain conditions, the resulting bounce could reveal the real inbox hiding behind the alias.

In fact, the researchers found almost no limit to the exposure. “We don’t know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable,” Tyler Murphy and Ben Weiner, co-founders of privacy service EasyOptOuts, wrote in their disclosure.

Advertisement

Two claimed fixes failed before this one

Murphy reported the flaw to Apple on June 11, 2025. Two days later, he sent the company detailed reproduction steps. Moreover, he flagged a second, similar vulnerability that July. Apple told him in March 2026 that it had resolved the issue. Murphy tested the feature and found the leak still worked. The company claimed another fix on June 30 — and again, the hole stayed open.

Everything changed once 404 Media published its investigation on July 1. Within two days, Apple deployed a patch that actually held. The outlet then verified the repair using its own masked addresses before publishing the technical details.

Why the patch does not close the book

The fix stops future leaks, but it cannot undo past ones. Murphy warns that aliases created before the patch may already sit in third-party mail server logs. As a result, any real address linked to an older alias could still surface later. Meanwhile, Apple has not published a security advisory or commented publicly on the timeline. That silence matters, because the company markets iCloud+ heavily on privacy — and a year-long gap between report and repair cuts against that pitch.

Apple’s quiet repair also lands during a rough stretch for its security reputation. For example, researchers recently caught a fake Maccy clipboard app stealing Mac passwords. Similarly, our breakdown of the Apple services upgrades hiding in iOS 27 shows how deeply iCloud+ now threads through the company’s ecosystem — which raises the stakes whenever one of its privacy tools breaks.