Loading article…
Apple’s Hide My Email feature has a security flaw that can reveal real user addresses. The bug, known for over a year, affects iCloud+ privacy protections.
Apple’s "Hide My Email" feature, designed to mask user identities, contains a vulnerability that allows attackers to uncover the real email addresses behind generated aliases [1]. The flaw, which has been known to Apple for more than a year, undermines the primary privacy promise of the iCloud+ service by potentially exposing personal contact information to data brokers and bad actors [2, 4].
| At a glance | |
|---|---|
| Product | Apple Hide My Email |
| Vulnerability | Real address exposure |
| Discovery Date | June 2025 |
| Current Status | Unpatched |
The vulnerability allows an attacker to trace a random, disposable @icloud.com address back to a user’s primary inbox [1]. Tyler Murphy, co-founder of the privacy service EasyOptOuts, first reported the issue to Apple in June 2025 [2]. Despite multiple communications, including a March 2026 update where Apple claimed the bug was resolved, the exploit remains functional [1, 4]. In controlled tests, researchers were able to link anonymous aliases to real accounts within five minutes [2].
The exposure carries significant risks, as leaked email addresses can be cross-referenced with publicly accessible people-search sites to harvest names, home addresses, and phone numbers [2, 4]. While Apple requested that the vulnerability remain undisclosed while they investigated, the lack of a fix led to the public disclosure of the flaw this week [1, 2]. Apple has not provided a definitive timeline for a patch [1].
Separately, Apple is transitioning its email relay infrastructure to a unified domain, moving from @icloud.com to @private.icloud.com [1, 3]. This shift, expected to roll out later this summer, will apply to future email IDs generated through both "Sign in with Apple" and "Hide My Email" [3].
While Apple states this change is intended to simplify account systems and email validation for developers, it introduces a new trade-off for users [1, 3]. The move to a standardized domain may make it easier for third-party services to identify and block signups originating from Apple’s privacy aliases [1, 2]. Existing accounts will continue to function on the older domain, and the change is primarily a backend adjustment rather than a security patch for the current vulnerability [3].
Until Apple confirms a fix, the privacy protections offered by Hide My Email may not be as robust as the company’s marketing suggests. The open question remains why a vulnerability reported over 12 months ago persists in a service marketed specifically for user anonymity [1, 2].
Coverage is mostly measured — 286 of 289 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 4 outlets · Aug 25, 2026 · How we report
Apple has announced an event scheduled for Wednesday, September 9, 2026, at 10 a.m. Pacific Time.
The streaming service now costs $14.99 per month or $119 per year.
John Ternus is preparing to take over as the CEO of Apple.
Deliveries and in-store availability for the new Mac mini and Mac Studio models are scheduled for September 22, 2026.