Wednesday, 22 July 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 22 July 2026 at 04:38

Apple reportedly fixes iCloud+ Hide My Email vulnerability

Apple has patched a vulnerability in iCloud+’s Hide My Email feature that could reveal users' real email addresses. The bug existed for at least a year, and Apple now faces a proposed class-action lawsuit.

Foto: Engadget

Apple has fixed a security flaw in its iCloud+ Hide My Email feature that made it easy to uncover the email addresses the service is designed to hide, 404 Media reports. The publication first reported the vulnerability in early July and revealed that Apple had known about it for at least a year.

Hide My Email was introduced in 2021 to allow users to generate disposable email addresses for added privacy. According to 404 Media, Apple deployed a software patch on July 3 that fully resolved the issue. Before the fix, it was possible to reveal a user’s email by sending a message to their hidden address that was rejected as spam, which exposed the real address.

Tyler Murphy, co-founder of EasyOptOuts who originally alerted 404 Media to the vulnerability, said the risk hasn’t been eliminated. “The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. However, we don't think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs,” Murphy said.

Engadget has contacted Apple for comment but has not yet received a response. Murphy first reported the issue to Apple in June 2025. Over several months, the company investigated and claimed to fix it, but Murphy was still able to find hidden addresses. He then contacted 404 Media. Apple’s public image heavily relies on its privacy commitment, making this flaw particularly problematic. According to PCMag, the company now faces a proposed class-action lawsuit over the vulnerability, seeking an injunction against Apple's “deceptive conduct” and full reimbursement of subscription fees paid by customers for the feature.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category