Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Sessions
July 22, 2026
Critical Windows NT OS Kernel Bug Lets Attackers Escalate Privileges
July 22, 2026
Critical AWS Kiro RCE Vulnerability Found in Website Text
July 22, 2026
Home/CyberSecurity News/Apple Patches Critical Hide My Email Flaw Exposing User Emails
CyberSecurity News

Apple Patches Critical Hide My Email Flaw Exposing User Emails

Key Takeaways Apple addressed a critical vulnerability in its iCloud+ “Hide My Email” service. The flaw could reveal users’ actual email addresses, compromising the feature’s...

Marcus Rodriguez
Marcus Rodriguez
July 22, 2026 3 Min Read
3 0

Key Takeaways

  • Apple addressed a critical vulnerability in its iCloud+ “Hide My Email” service.
  • The flaw could reveal users’ actual email addresses, compromising the feature’s privacy promise.
  • Independent researcher Tyler Murphy discovered the bypass, which remained unpatched for over a year.
  • A fix was deployed on July 3, 2026, but previously exposed aliases may still pose risks.

Apple Patches Critical Hide My Email Flaw Exposing User Data

Apple has rolled out a crucial security update to rectify a significant vulnerability within its iCloud+ “Hide My Email” functionality. This critical flaw had the potential to expose the real email addresses of users, directly undermining the primary privacy benefit offered by the service.

Table Of Content

  • Key Takeaways
  • Apple Patches Critical Hide My Email Flaw Exposing User Data
  • Understanding Hide My Email
  • Apple’s Remediation Efforts
  • What You Should Do

The vulnerability, which reportedly persisted for more than a year, allowed malicious actors to ascertain a user’s genuine email address from the anonymous aliases generated by Apple’s Hide My Email system.

The issue gained prominence after Tyler Murphy, an independent researcher and co-founder of EasyOptOuts, identified a method to consistently bypass the feature under specific circumstances.

Understanding Hide My Email

Apple’s Hide My Email service is designed to bolster user privacy by creating unique, randomized email aliases. These aliases forward incoming messages to a user’s primary inbox without revealing their actual email address to third parties. Typically, these generated addresses combine random words and numbers, followed by the @icloud.com domain, preventing external entities from linking or correlating a user’s true email identity across various online services or potential data breaches.

However, Murphy’s investigation revealed that by crafting and sending an email specifically designed to trigger standard spam filtering mechanisms, it was possible to inadvertently disclose the recipient’s authentic email address. In such scenarios, even if the message never reached the user’s inbox, underlying address information could be leaked through email handling systems or mail transfer logs.

Apple’s Remediation Efforts

Murphy stated that his testing achieved a 100% success rate in exposing real email addresses across multiple samples. He responsibly disclosed the vulnerability to Apple in June 2025. Despite ongoing communications, the flaw remained exploitable for several months. Apple reportedly acknowledged the issue multiple times but did not fully remediate it until recently.

According to 404 Media reports, Apple deployed a patch for the vulnerability on July 3, 2026, following increased public scrutiny, and confirmed that the fix addresses the core issue. Nonetheless, security researchers caution that some residual risks might still exist.

Given that email infrastructure frequently retains logs, it is possible that previously exposed email addresses could persist in third-party systems. Any alias created prior to early July 2026 might have already been compromised without the user’s awareness.

The public disclosure of this vulnerability has also led to a class-action lawsuit against Apple. The suit alleges deceptive marketing practices regarding Hide My Email, claiming it was promoted as a secure privacy feature while being vulnerable. Plaintiffs are seeking compensation for iCloud+ subscription costs and demanding corrective measures.

This incident underscores the inherent complexities of implementing privacy-preserving technologies within intricate email ecosystems. Even robust anonymization features can falter due to interactions with legacy systems such as spam filters, bounce handling mechanisms, and logging infrastructure. For users, the risk of exposure highlights the critical need for multifaceted privacy strategies. While tools like Hide My Email effectively mitigate tracking and correlation risks, they should not be considered the sole defense against identity exposure.

What You Should Do

  • If you created “Hide My Email” aliases before July 2026, consider these aliases potentially compromised.
  • Rotate or delete sensitive aliases and create new ones.
  • Monitor your primary email inbox and associated accounts for any suspicious activity, phishing attempts, or unauthorized access.
  • Enable two-factor authentication (2FA) on all critical online accounts to add an extra layer of security.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

SolarWinds Patches 15 Critical Serv-U Flaws Allowing Root Access

Next Post

Cloudflare Data Shows Which World Cup Teams Drove Global Internet Traffic

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Royal Ransomware Leverages Qbot, Cobalt Strike to Rapidly Compromise Windows Domains
July 22, 2026
Cloudflare Data Shows Which World Cup Teams Drove Global Internet Traffic
July 22, 2026
Apple Patches Critical Hide My Email Flaw Exposing User Emails
July 22, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us