Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Apple fixes Hide My Email bug exposing real addresses in mail logs.
Summary
Apple has patched a vulnerability in its Hide My Email service that could expose users' real email addresses in mail logs when emails were rejected as spam. The flaw was reported over a year ago and was fixed on July 3, 2026, after multiple unsuccessful attempts. This fix comes as Apple faces a class-action lawsuit alleging it misled customers about the privacy of the feature.
Full text
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Ravie LakshmananJul 21, 2026Vulnerability / Cloud Security Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was disclosed to the company by Tyler Murphy, co-founder of EasyOptOuts. Hide My Email generates unique, random email addresses that forward messages to a user's personal email inbox automatically. By creating disposable email addresses, the idea is to safeguard user privacy and tackle unwanted spam. The feature requires a paid subscription to iCloud+ and was announced by Apple in June 2021. However, at the start of the month, details emerged of a flaw that made it possible to unmask a user's real email address hidden behind a Hide My Email address. The issue was first reported to Apple on June 13, 2025, with Apple unsuccessfully attempting to patch it earlier this March and again on June 30, 2026. Although specifics about the issue were withheld at that time to avoid potential exploitation, more details have now been published given it has been finally plugged. The crux of the problem was that simply sending a targeted Hide My Email user a message that got rejected as spam caused the person's real email address to appear in email logs. "We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can't review your spam folder to learn whether you were affected," Murphy and EasyOptOuts co-founder Ben Weiner told 404 Media. It bears noting that while the bug has been resolved, it's possible that a real email address linked to a Hide My Email address created before July 7, 2026, may have been captured in mail transfer logs when non-malicious emails get bounced. The development comes as Apple is facing a class action lawsuit, accusing it of misleading customers about the privacy of its Hide My Email feature while charging for it. "Apple promised Hide My Email as a privacy feature customers paid for, whether directly through iCloud+ or indirectly through Apple's product-wide privacy representations, and failed to deliver it," according to the complaint. "Worse, Apple has been fully aware of this problem for over a year and has not fixed it." "At no point during this period did Apple disable or pause Hide My Email, warn its customers of the flaw, or correct its privacy representations." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE Apple, Cloud security, Consumer Security, Data Exposure, Digital Identity, email security, icloud, Privacy, security update, Vulnerability ⚡ Top Stories This Week URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code ⭐ Featured Resources What Security Teams Must Defend in the New AI Software Supply Chain Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See