Apple finally fixed the Hide My Email vulnerability that allowed outsiders to unmask a user’s real address behind an alias. The patch went live on July 3, closing a loophole that Apple knew about for more than a year.
The fix landed only after the bug became public — and a class-action lawsuit followed close behind. But the bigger question is: Why did it take outside pressure to get Apple to fix it?
How the Hide My Email vulnerability worked
The iCloud+ feature Hide My Email works by generating random addresses that forward messages to your real inbox, meaning no one knows where mail actually lands. The idea is that you can sign up for email lists or services without revealing your real email address — a protective measure against spam and other bad behavior.
But Apple’s system broke down when something specific happened. If a message sent to a hidden alias got bounced or was flagged as spam, the rejection could leak the real email address behind it.
Unfortunately, this made it easy for the Hide My Email flaw to go unnoticed by users. A bounced email rarely shows up in your inbox. And since there was nothing obvious to spot in your spam folder, most people never noticed.
A yearlong wait for a fix
Security researcher Tyler Murphy, a co-founder of EasyOptOuts, first flagged the Hide My Email problem in June 2025. Apple said it issued a fix, but Murphy later found out the exploit still worked.
The cycle repeated for months, and Apple finally shipped a real fix only after the flaw became public knowledge.
“We don’t know how often hidden email addresses were leaked in email logs,” Murphy and his EasyOptOut co-founder Ben Weiner told 404 Media in a statement published Tuesday. “For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message.”
And even now, the risk isn’t fully gone. Any alias created before July 7, 2026, may have already leaked into third-party mail server logs that Apple can’t scrub.
Apple’s privacy promise triggers lawsuit over Hide My Email vulnerability
The fallout has already reached the legal sphere. As Cult of Mac reported earlier this month, Apple is facing a proposed class-action lawsuit over the Hide My Email flaw. The suit accuses the company of selling privacy it couldn’t deliver — with Hide My Email at its center.
The timing is notable. Apple said it will unify the domains behind Hide My Email and Sign In with Apple later this year. While that move has nothing to do with this bug, it shows how much backend work is happening around these privacy tools.
What this means for you
If you use Hide My Email heavily, there’s not much you can do today. The hole is patched, and Apple says the fix now fully resolves the problem going forward.
Still, older aliases remain a big concern. If you created one before July, it will be slightly less anonymous than it used to be, especially for senders whose emails might have bounced.


