Apple Patches 'Hide My Email' Flaw That Exposed User Identities
Apple has finally addressed a critical privacy vulnerability in its **Hide My Email** service, a feature designed to mask users' real email addresses. For over a year, a flaw allowed actual email identities to be unmasked, undermining the service's core privacy promise and potentially exposing users to unwanted spam and tracking. The fix comes amidst a class-action lawsuit alleging that Apple misled customers about the feature's privacy assurances.

**Apple** has deployed a fix for a significant security flaw within its **Hide My Email** service, which could expose users' genuine email addresses. The issue directly contradicted the privacy guarantees of the feature, which generates unique, random email addresses to forward messages to a user's personal inbox, aiming to reduce spam and protect identity.
## The Unmasking Vulnerability
The vulnerability, first reported to **Apple** on June 13, 2025, by **Tyler Murphy**, co-founder of **EasyOptOuts**, allowed a user's real email address to be revealed in specific scenarios. Details of the flaw were initially withheld to prevent exploitation but have now been published following the successful patch.
According to **404 Media**, the core of the problem lay in how rejected emails were handled. If a message sent to a **Hide My Email** address was rejected as spam, the recipient's actual email address could appear in email logs.
"We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message," **Murphy** and **EasyOptOuts** co-founder **Ben Weiner** told **404 Media**. "Such emails probably didn't make it to your inbox, so you can't review your spam folder to learn whether you were affected."
## Timeline of the Fix
**Apple** reportedly attempted to patch the vulnerability in March 2026 and again on June 30, 2026, before finally deploying a successful fix on July 3, 2026. This means the flaw persisted for over a year after its initial disclosure.
While the bug is now resolved, it's crucial to note that any real email addresses linked to **Hide My Email** addresses created before July 7, 2026, may have been captured in mail transfer logs if non-malicious emails bounced.
## Legal Ramifications
The resolution of this bug comes as **Apple** faces a class-action lawsuit. The lawsuit accuses the tech giant of misleading customers about the privacy of its **Hide My Email** feature, especially given that it is a paid component of **iCloud+**.
"Apple promised Hide My Email as a privacy feature customers paid for, whether directly through iCloud+ or indirectly through Apple's product-wide privacy representations, and failed to deliver it," the complaint states. "Worse, Apple has been fully aware of this problem for over a year and has not fixed it."
Furthermore, the lawsuit alleges, "At no point during this period did Apple disable or pause Hide My Email, warn its customers of the flaw, or correct its privacy representations." This legal challenge highlights the significant trust placed in privacy features and the implications when they fail to deliver on their promises.