Apple fixed a vulnerability in Hide My Email that exposed a user’s real email address, reports 404 Media. Apple told the site that the issue was fully fixed in a patch released on July 3.
The Hide My Email vulnerability was brought to Apple’s attention in June 2025, but the company did not patch it until 404 Media made the bug public in early July.
EasyOptOuts co-founder Tyler Murphy, who first reported the flaw to Apple, said he was told it was under investigation. Apple told him the vulnerability had been fixed in March 2026, but that wasn’t the case. In the following months, Apple said it was investigating the problem again, but Murphy wasn’t convinced Apple was actually going to fix it, so he contacted 404 Media to make it public.
404 Media has confirmed that the vulnerability has been fixed and has now shared details on how it works, as it can no longer be exploited. Hide My Email is a paid iCloud+ feature that allows users to create an anonymous email address for website registrations and email correspondence.
Sending a targeted Hide My Email user a message that was rejected as spam resulted in the person’s real email address appearing in email logs.
“We don’t know how often hidden email addresses were leaked in email logs. For many large email hosts, the leak was triggered simply by an email being automatically dismissed as spam, even if it was a legitimate message. Such emails likely didn’t make it to your inbox, so you can’t check your spam folder to see if you were affected,” said Ben Weiner, co-founder from EasyOptOuts, in a new press release.
“The bug that caused Apple’s Hide My Email to disclose hidden email addresses to senders has been fixed. However, we do not believe the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail forward logs are often retained, we would assume that any hidden email addresses linked to a Hide My Email address created before July 7 2026, may have been exposed and could still be in third-party journals,” they said. added.
Although the bug has now been fixed, email logs from before the patch could still expose users’ email addresses.
Apple has been sued over the Hide My Email flaw, and the plaintiffs are seeking class-action status. The lawsuit claims that Apple violated California’s False Advertising Law and other consumer protection laws because Apple knew that Hide My Email did not work as advertised.
