Apple said it deployed a fix after a vulnerability in its Hide My Email feature was publicly reported. A proposed class action lawsuit was later filed over the issue, alleging that the flaw exposed users' authentic email addresses.
Lead
Apple stated it deployed a server-side patch on July 3, 2026, to address a security vulnerability within its iCloud+ "Hide My Email" feature. The issue permitted real email addresses to be exposed during automated message rejections. Apple later said it had deployed the server-side update after 404 Media reported the vulnerability.
Inside the Issue
Hide My Email is a privacy-focused feature bundled within Apple's paid iCloud+ subscription. It allows users to generate randomized @icloud.com email aliases that forward incoming correspondence to their primary personal inbox, masking their real email address from third-party services and senders.
A technical flaw in the forwarding pipeline caused the system to reveal a user's real email address in server logs when an incoming message sent to an alias was rejected or bounced as spam. Because mail servers handle these automated rejections silently, affected users received no notification in their standard inbox or spam folders indicating that their primary email address had been recorded in delivery logs.
Timeline of Disclosures
The vulnerability was originally discovered in June 2025 by Tyler Murphy, co-founder of EasyOptOuts, who submitted his findings to Apple's security team.
June 2025: Murphy discovered the vulnerability and submitted a report to Apple.
July 2025 – June 2026: Apple investigated the issue and stated it had implemented a fix. Murphy said subsequent testing indicated the vulnerability remained exploitable.
Early July 2026: Approximately one year after the initial report, Murphy contacted 404 Media, which published an article regarding the unpatched flaw.
July 3, 2026: Apple deployed a server-side software patch, which the company later told reporters had resolved the vulnerability.
According to Murphy, all aliases tested during his initial controlled evaluations with volunteers exposed the underlying email address when subjected to the bounce condition.
Mechanics of the Exposure
The information disclosure was triggered through standard mail transfer operations rather than direct account breaches:
A sender dispatched a message to a Hide My Email alias.
The receiving mail system automatically rejected or bounced the message as spam.
Standard mail transfer logs generated during the bounce recorded the recipient's underlying personal email address.
Company Response and Residual Risk
Apple informed 404 Media that it deployed a patch on July 3, 2026, stating that the update resolved the vulnerability.
Following the fix, Murphy and EasyOptOuts co-founder Ben Weiner issued a statement regarding legacy data risks:
"The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. However, we don't think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs
are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been expose d and could still be in third-party log s."
Legal Proceedings
According to PCMag, a proposed class action lawsuit, Alvarez v. Apple Inc., was filed against Apple in federal court following the public disclosures.
The complaint accuses Apple of false advertising, fraud, and breach of contract for charging a subscription fee for a privacy feature that failed to maintain address anonymity. The suit seeks full recovery of iCloud+ subscription fees paid by affected customers and an injunction against the company.
What It Means for Users
Active Protection: Apple's July 3 patch addresses active address disclosure during message bounces.
Legacy Log Retention: Murphy and Ben Weiner noted that aliases generated prior to July 7, 2026, may have historical records retained in external mail server transfer logs.
User Recommendations: Murphy and Weiner suggested that subscribers who relied on older aliases for sensitive services consider creating new aliases to avoid potential association with archived server logs.
Sources
Primary Source
Additional Reporting
.png)
0 Comments