Apple Finally Patches the ‘Hide My Email’ Flaw (But Is the Damage Done?)
Jesse Hollington / iDrop News
Toggle Dark Mode
Apple has finally patched a vulnerability that could expose the real email addresses hidden behind Apple’s private “Hide My Email” addresses.
It’s likely the flaw has existed since Apple began issuing private email addresses. It was reported to Apple a year ago by security researcher Tyler Murphy, the co-founder of EasyOptOuts, but only became broader public knowledge earlier this month, when Murphy decided to go public to prompt Apple to take action.
Murphy reached out to 404 Media’s Joseph Cox in late June, and was able to prove the exploit still existed simply by asking Cox to generate a new Hide My Email address and provide it to Murphy. “Around five minutes later, he replied with my real email address linked to my Apple account which was supposed to be hidden,” Cox said in his report.
While the specific steps to replicate the exploit weren’t disclosed, for obvious security reasons, the process doesn’t appear to involve any of the usual methods by which hidden email addresses are leaked. Cox apparently had to do nothing more than provide the address itself as a string of characters. There’s no indication he sent or received any emails using the newly generated address.
However, once the existence of the flaw was revealed, it wasn’t too hard for others with knowledge of how email systems work to figure it out. As someone who has been building email servers since before most people knew what email was, it only took me about three minutes of testing a hypothesis of my own to find the same flaw Murphy likely discovered, which did involve sending an email to a Hide My Email address — just not one that the recipient was likely to see.
According to documentation provided by Murphy, Apple acknowledged this issue in July 2025, and claimed it had addressed it in March 2026. However, Murphy checked Apple’s homework, discovered it hadn’t actually been fixed, and followed up with Apple, providing more information. The company thanked him for his assistance, told him it was “still investigating this issue,” and politely requested he not disclose it.
By June, Murphy figured he’d given Apple enough time, and decided it was time to both alert the public to these risks and put more pressure on Apple.
Unsurprisingly, the disclosure also prompted a class-action lawsuit accusing Apple of false advertising for knowingly selling a privacy feature that didn’t actually offer any privacy. While that lawsuit felt a bit opportunistic — none of the plaintiffs could demonstrate how they’d been harmed by this — it still likely helped light a fire under someone at Apple.
Of course, it’s also worth mentioning that there are limits to the expectation of privacy when it comes to Hide My Email. The feature creates a random address that will automatically forward inbound emails to a user’s real email address. This can be used with just about any email service, as it’s simple forwarding, although iCloud users can also more easily send and reply to messages using the hidden address. Sign in with Apple uses a similar arrangement when users opt for a private address.
Both services are primarily intended to reduce spam and provide a modicum of anonymity for internet communications by keeping your real email address off mailing lists. If a Hide My Email or Sign in with Apple email starts getting spam, you’ll have a pretty good idea of where it came from, and you can deactivate or delete the offending address. However, it’s not truly anonymous, as one bright spark learned when he thought he could use Hide My Email to threaten the FBI director’s girlfriend.
How It Worked
Apple recently confirmed to 404 Media that it deployed a patch on July 3, which has “fully resolved the issue.”
Now that the vulnerability has been fixed, 404 Media has disclosed the nature of Murphy’s flaw, and it’s precisely what I discovered:
Now Apple says it has been fixed, we can add that, in simple terms, it required sending a target Hide My Email user a message that got rejected as spam. “We don’t know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn’t make it to your inbox, so you can’t review your spam folder to learn whether you were affected,” Murphy and EasyOptOut co-founder Ben Weiner said in a new statement.
Joseph Cox, 404 Media
Since Hide My Email is a forwarding service, it simply takes anything it receives and passes it on to the real email host. If those messages are bounced or refused, that’s done by the final destination, not the intermediate Hide My Email server. While this doesn’t always result in a bounced message back to the original sender, it is recorded in a mail server’s logs.
While the issue no longer exists, Murphy told 404 Media that older addresses should still be treated as potentially compromised, since the problem was so basic that thousands of mail server logs could still contain details linking Hide My Email addresses with the real addresses behind them.
“Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained,” Murphy and his partner, Ben Weiner, said, “we’d assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs.”

