Steps have been taken by Apple to address a security flaw in its Hide My Email service whereby it had become possible for users' actual email addresses to be revealed. A fix was deployed by Apple on July 3, 2026, after more than a year.
The flaw was disclosed to Apple by Tyler Murphy, co-founder of EasyOptOuts. When the company failed to patch it promptly, the details eventually became public.
How the Feature Works
Hide My Email generates unique, random email addresses that forward messages to a user's personal email inbox automatically. This concept aims at ensuring privacy of the users and removing spam through disposable emails. The feature requires a paid subscription to iCloud+ and was announced by Apple in June 2021.
The Flaw
The problem was straightforward. Simply sending a targeted Hide My Email user a message that got rejected as spam caused the person's real email address to appear in email logs. The spam rejection triggered the leak.
The issue was first reported to Apple on June 13, 2025. Apple unsuccessfully attempted to patch it earlier this March and again on June 30, 2026. The third attempt finally worked.
How Many Were Affected
It is not known how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably did not make it to the user's inbox, so the user could not review their spam folder to learn whether they were affected.
While the bug has been resolved, a real email address linked to a Hide My Email address created before July 7, 2026, may have been captured in mail transfer logs when non-malicious emails got bounced.
The Class Action Lawsuit
Apple is now facing a class action lawsuit over the flaw. The complaint accuses Apple of misleading customers about the privacy of its Hide My Email feature while charging for it.
Apple promised Hide My Email as a privacy feature customers paid for, whether directly through iCloud+ or indirectly through Apple's product-wide privacy representations, and failed to deliver it. The company has been fully aware of this problem for over a year and has not fixed it until recently.
At no point during this period did Apple disable or pause Hide My Email, warn its customers of the flaw, or correct its privacy representations.
The Bottom Line
The Apple Hide My Email privacy flaw is a reminder that privacy features are only as good as their implementation. A simple spam rejection could unmask a user's real address. The fix came more than a year after the initial disclosure.
If you used Hide My Email before July 7, 2026, your real address may have been exposed in mail logs. Apple did not warn you. The class action lawsuit will determine whether that silence was a violation of trust.
FAQ Section
What is Hide My Email?
Hide My Email is an iCloud+ feature that generates unique, random email addresses that forward to a user's personal inbox. Its purpose was to secure the information and prevent spam.
What was the flaw?
The flaw revealed real email addresses in the log of emails if a spam rejection happened for an email addressed to a Hide My Email address.
When did the flaw get patched?
The patch for this flaw was released by Apple on July 3, 2026, which was about a year and some months after the finding of this vulnerability.
For how long did Apple know about the flaw?
This flaw was discovered by Apple from June 13, 2025.
Was I affected?
If you used a Hide My Email address created before July 7, 2026, your real email address may have been captured in mail transfer logs.