Connect with us

News

Apple Needed Four Tries to Truly Fix Its Hide My Email Leak

Apple calls its Hide My Email patch complete, but independent testing and two earlier false fixes show why old exposures may be permanent.

Published

on

Apple says the vulnerability that let strangers unmask the real email address behind a Hide My Email alias is fixed, patched on July 3. AppleInsider reproduced the same flaw two weeks later, on July 17, the latest independent test to catch Apple’s “resolved” claim falling short.

The bug turned a privacy feature bundled into paid iCloud+ subscriptions into something closer to a leak waiting to happen. Apple knew about it for more than a year before 404 Media published the first account of it in early July. Even now, the patch cannot undo addresses already sitting in mail logs Apple does not control.

Apple’s July 3 Fix Meets a July 17 Retest

Apple told 404 Media it deployed a patch on July 3 and that the fix “fully resolved” the issue. That would normally close the story. It has not.

AppleInsider said it reproduced the same exploit on July 17, two weeks after Apple’s claimed repair date, finding that a sender holding a specific Hide My Email alias could still uncover the real address behind it. By July 21, the outlet could no longer reproduce the flaw, which suggests the actual fix landed sometime after that retest rather than on the date Apple gave reporters.

Apple has not explained why the two dates do not match, or whether the July 3 patch rolled out in stages across its servers.

  • Apple told 404 Media the July 3 patch fully resolved the vulnerability, describing no residual risk.
  • Tyler Murphy and Ben Weiner of EasyOptOuts say the underlying bug is fixed but the exposure risk to users is not eliminated, since bounced messages already logged real addresses before the patch existed.
  • AppleInsider reproduced the flaw on July 17 and says it cannot explain the gap without more detail from Apple.

None of the three accounts contradicts the others outright. They simply describe different points on the same timeline, which is itself the problem for anyone trying to pin down when the risk actually ended.

A Year of Fixes That Weren’t

This is not the first time Apple told researchers a fix was in place only to be proven wrong. EasyOptOuts, the personal data removal service Murphy co-founded with Weiner, laid out a dated log of its year of correspondence with Apple after the first 404 Media story ran.

  1. June 11, 2025: EasyOptOuts discovers a flaw in Hide My Email and reports it to Apple.
  2. June 13, 2025: The researchers send a detailed report with reproduction steps.
  3. July 9, 2025: EasyOptOuts flags a second, related vulnerability.
  4. July 14, 2025: Apple sends its first message acknowledging the reports are under review.
  5. March 3, 2026: Apple tells the researchers the vulnerabilities are fixed and asks them to verify.
  6. March 19, 2026: EasyOptOuts reproduces the flaw again using its original steps.
  7. June 30, 2026: Apple’s second claimed fix is also found still exploitable, EasyOptOuts says.
  8. July 1, 2026: 404 Media publishes its first report, withholding technical detail because the bug is still live.
  9. July 3, 2026: Apple tells 404 Media it has deployed a patch that fully resolves the issue.
  10. July 15, 2026: Anthony Alvarez files a proposed class action against Apple in federal court.
  11. July 17, 2026: AppleInsider reproduces the exploit despite the claimed fix.
  12. July 21, 2026: AppleInsider can no longer reproduce the flaw, and EasyOptOuts publishes a new warning about historical exposure.

Murphy also suggested at one point that Apple temporarily suspend new Hide My Email address creation while it worked on a lasting fix. Nothing indicates Apple acted on that suggestion.

How a Bounced Spam Message Unmasked an Address

The mechanism, once explained, sounds almost mundane. Sending a Hide My Email user a message that got rejected as spam was enough to expose the real address behind the alias, in simple terms, according to Murphy and Weiner.

Many major email providers log the true destination address when a message bounces, even when that message was legitimate. That log entry, not a hack or a data breach, was the leak.

Because rejected mail never reaches an inbox, affected users had no way to notice. “We don’t know how often hidden email addresses were leaked in email logs,” Murphy and Weiner wrote in their joint statement. “Such emails probably didn’t make it to your inbox, so you can’t review your spam folder to learn whether you were affected.”

The Exposure This Patch Cannot Undo

A patch closes a mechanism going forward. It cannot reach back into mail servers Apple never controlled in the first place.

Murphy and Weiner said any hidden address linked to a Hide My Email alias created before July 7, 2026, should be treated as potentially exposed, with a copy possibly still sitting in a third party’s retained mail transfer logs.

Alias Status Risk After the July 3 Patch
New Hide My Email address created after the patch Protected; the bounce-triggered leak mechanism is closed, per Apple and EasyOptOuts
Existing address created before July 7, 2026 Real address may already be recorded in a third party’s mail logs, with no way for the user to confirm it
Any address that ever triggered a bounce or spam rejection Highest risk category, per Murphy and Weiner, since the leak never required a malicious sender

Apple has not said how many addresses might be affected and has not committed to notifying customers individually about the exposure window.

Alvarez v. Apple Puts a Price on Broken Privacy Promises

Anthony Alvarez filed a proposed class action against Apple on July 15 in the U.S. District Court for the Northern District of California, days before AppleInsider’s retest complicated the company’s timeline further.

Alvarez’s complaint leans on the same pattern EasyOptOuts documented: Apple calling the bug fixed more than once before it wasn’t. Apple’s two earlier claims of a fix that hadn’t landed already anchor the case’s core argument.

  • False advertising: the suit says Apple marketed Hide My Email as private while the alias could be traced back to a real address.
  • Fraud: the complaint argues customers paid for a feature Apple could not actually deliver.
  • Breach of contract: Alvarez says Apple’s own privacy commitments amount to a promise it broke.
  • California consumer protection violations: the suit ties the alleged conduct to state law covering deceptive business practices.

Alvarez does not allege that anyone used the flaw against him personally. His claimed injury is financial. He says he bought an iPhone and subscribed to Apple’s 200GB iCloud+ tier around March 15, 2025, and would not have paid as much had he known Hide My Email could fail.

The suit seeks to represent four proposed classes of U.S. Apple customers, including two California subclasses, covering both the full iCloud+ feature and the more limited relay addresses issued through Sign in with Apple. Security Boulevard reported the case could seek more than $5 million in damages, plus a jury trial and an order requiring Apple to fix Hide My Email or clearly disclose its limits. Apple has not commented publicly on the lawsuit.

Rotating Old Aliases Is the Only Move Left

For a bug like this, there is no retroactive fix a user can apply. The leak already happened, if it happened, before anyone could check.

Treating any Hide My Email address created before July 7, 2026, the cutoff Murphy and Weiner cite, as potentially linked to a real inbox in someone else’s records is the safest assumption for now. Apple’s own settings for deactivating and recreating Hide My Email addresses let a user retire an old alias and generate a fresh one for any account that matters.

That does not erase what is already logged elsewhere. It only stops the same address from being exposed twice.

Frequently Asked Questions

When Did Apple Launch Hide My Email?

Apple introduced Hide My Email in 2021 alongside iCloud+, letting subscribers generate throwaway addresses ending in @icloud.com that forward to a real inbox. Apple’s support page for the feature still describes it as a way to keep a personal address private when signing up for accounts.

Does the Flaw Also Affect Sign in with Apple?

Yes. The class action covers both the full Hide My Email feature bundled with paid iCloud+ plans and the more limited relay addresses Apple generates automatically through Sign in with Apple, which use a separate @privaterelay.appleid.com domain rather than @icloud.com.

How Much Does an iCloud+ Plan with Hide My Email Cost?

The complaint cites iCloud+ pricing ranging from $0.99 to $59.99 a month depending on storage tier, with Hide My Email included at every paid level rather than sold as an add on.

Has a Court Certified the Class Action Against Apple?

No. As of the case’s July 15 filing, no class had been certified and the allegations remain untested in court. Alvarez is asking for a jury trial and an order requiring Apple to either fix Hide My Email or clearly disclose its limitations.

I’m a creative thinker, writer, and social media professional who loves sharing tips and ideas to help small businesses grow. My mission is to empower business owners with the knowledge they need to succeed online. I’m passionate about the internet and social media and want to share what I know with others to help them navigate the waters of online business, marketing, and blogging.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending