Apple fixes Hide My Email flaw that could expose real addresses

by

Apple has fixed a flaw in its Hide My Email service that could expose a user’s real email address in mail logs, according to a report Tuesday. The bug was patched on July 3, 2026, after it had been disclosed more than a year earlier.

KEY FACTS

  • Feature Hide My Email creates random forwarding addresses for iCloud+ subscribers.
  • Bug A rejected message could reveal the user’s real address in email logs.
  • Timeline The issue was reported to Apple on June 13, 2025.
  • Patch Apple attempted fixes in March and again on June 30, 2026 before resolving it on July 3.

The feature is designed to forward messages from disposable addresses to a user’s personal inbox automatically, limiting spam and reducing exposure of a real email address. Apple introduced it in 2021 as part of iCloud+.

The disclosure said the problem could appear when a message sent to a Hide My Email address was rejected as spam. In those cases, the underlying real address could show up in email logs even if the message never reached the inbox.

Tyler Murphy, co-founder of EasyOptOuts, first disclosed the issue to Apple, and a follow-up report said the flaw may have affected addresses created before July 7, 2026 if legitimate messages were bounced or automatically rejected.

Apple is also facing a class action lawsuit over claims that it misled customers about the privacy protections of Hide My Email while charging for the feature. The complaint says the company knew about the problem for over a year and did not warn users.

WHY IT MATTERS

The fix closes a privacy gap in a feature meant to hide a user’s real contact details, but the disclosure says some older addresses may already have been exposed in mail transfer logs. Users who relied on the service for privacy may not know whether their address was captured.