- Apple fixed a flaw in its Hide My Email service on July 3, 2026, after it was disclosed over a year prior.
- The bug could unmask a user’s real email address in mail logs when a message was rejected as spam.
- Apple now faces a class action lawsuit alleging it misled customers about the feature’s privacy protections.
Apple deployed a fix on July 3, 2026, for a security flaw in its Hide My Email service that could expose users’ real email addresses, undermining the feature’s core privacy promise. The vulnerability, reported by 404 Media, was first disclosed to Apple on June 13, 2025, by Tyler Murphy, co-founder of EasyOptOuts.
Hide My Email generates unique, random addresses that forward messages to a user’s personal inbox, requiring a paid iCloud+ subscription. However, simply sending a targeted user a message that got automatically rejected as spam caused their real email address to appear in email logs.
“We don’t know how often hidden email addresses were leaked in email logs,” Murphy and co-founder Ben Weiner told 404 Media. They noted the leak was triggered even for legitimate messages, adding, “Such emails probably didn’t make it to your inbox, so you can’t review your spam folder.”
Apple unsuccessfully attempted to patch the bug in March 2026 and again on June 30, 2026, before finally resolving it days later. Consequently, any real email address linked to a Hide My Email address created before July 7, 2026, may have been captured in mail transfer logs.
Meanwhile, Apple is facing a class action lawsuit accusing it of misleading customers. “Apple promised Hide My Email as a privacy feature customers paid for…and failed to deliver it,” the complaint states, adding that Apple did not disable the service or warn users during the year-long vulnerability window.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
