Apple patches Hide My Email leak after year-long delay
TL;DR
- Tyler Murphy of EasyOptOuts reported the flaw to Apple in June 2025; Apple did not ship a patch until July 3, 2026.
- The exploit worked by sending a Hide My Email user a message crafted to be rejected as spam, exposing the real underlying address.
- A class action lawsuit has been filed seeking iCloud+ subscription cost recovery and an injunction over the deceptive conduct claim.
A privacy feature you pay for should probably not leak the exact thing you are paying it to hide. That is the awkward story out of Cupertino this week. 404 Media reports that Apple has quietly patched a bug in Hide My Email, the iCloud+ alias service, more than a year after it was first reported.
The reporter for the flaw is Tyler Murphy, co-founder of EasyOptOuts, who disclosed the issue to Apple in June 2025. The mechanic, according to 404, was straightforward. Send a Hide My Email user a message crafted to be rejected as spam, and the real underlying address could leak back out to the sender. In tests the researcher ran with volunteers, 100 percent of Hide My Email addresses were found to be exploitable. Apple acknowledged the report about a month after receiving it and said it was investigating, then went quiet, and Murphy eventually took the story public because, in his words, 'we don't feel comfortable waiting any longer.'
The patch shipped on July 3, 2026, and Apple's line is that it 'has fully resolved the issue.' The uncomfortable part is what happened during the year in between. Murphy and his co-founder Ben Weiner point out that 'we don't know how often hidden email addresses were leaked,' and that any address created before July 7, 2026 may already have been exposed. A class action has been filed seeking subscription cost recovery and an injunction against Apple on a deceptive-conduct claim.
The honest caveat is that the reporting does not tell you what triage priority Apple originally assigned the bug, why the fix took as long as it did, or how many real addresses ended up in strangers' mail logs. Those numbers may never surface. What you can act on today is smaller and more practical. If you use Hide My Email for anything you genuinely want kept anonymous, aliases created before this month should be treated as potentially compromised, and rotating them is the cheap move. For competing alias providers, this is a rare open door to compete on disclosure hygiene rather than on features.
Shared on Bluesky by 3 AI experts
-
Apple knew that their feature, Hide My Email (which is literally supposed to hide your real email), left users' emails exposed for more than a year. After @josephcox.bsky.social wrote about in early July, the company fin…
View on Bluesky →
Originally reported by 404media.co
Read the original article →Original headline: Apple Patches Hide My Email Vulnerability That Leaked Users' Real Addresses via Rejected Spam Mail