
Apple has patched a vulnerability in its iCloud+ Hide My Email feature that made it surprisingly easy to uncover the real email addresses the service is supposed to protect. According to Engadget, the fix came after 404 Media first reported the issue in early July, revealing that Apple had known about the problem for at least a year before acting.
Hide My Email launched in 2021 as part of iCloud+. The idea is simple: instead of giving out your real email address when signing up for apps or websites, the feature generates a random dummy address that forwards messages to your inbox. It is one of Apple’s most visible privacy tools, and the company has leaned on privacy as a core part of its brand for years.
The flaw made that promise much harder to keep. Before Apple’s patch, someone could send a message to a Hide My Email address, have it bounce back as spam, and in doing so see the user’s actual email address. Apple says it deployed a software fix on July 3 that fully resolved the issue.
Tyler Murphy, co-founder of data removal service EasyOptOuts, is the person who first flagged the vulnerability to 404 Media. He told Apple about the problem back in June 2025. Over the following months, the company looked into it and at one point claimed to have fixed it. When Murphy was still able to find hidden email addresses, Apple said it would look into the issue again. Eventually, concerned the company might leave it unpatched, he went public.
Murphy is cautious about declaring the problem fully resolved, even now. His statement is worth reading in full:
- The bug that caused email addresses to leak to senders has been fixed.
- But non-malicious emails can also bounce, which could have revealed hidden addresses before the patch.
- Mail transfer logs are often kept by third parties, sometimes for years.
- His conclusion: any Hide My Email address created before July 7, 2026, should be considered potentially exposed and possibly still sitting in third-party logs.
That is a significant caveat. It means users who relied on Hide My Email to protect their identity over the past several years may have had their real addresses quietly collected without knowing it. The patch stops the leak going forward, but it cannot undo what may already be out there.
The fallout is already moving beyond a technical fix. PCMag reports that Apple now faces a proposed class action lawsuit over the vulnerability. The lawsuit seeks an injunction against what it calls Apple’s ‘deceptive conduct’ and full reimbursement of subscription fees paid by iCloud+ customers who used the feature. That is a direct challenge to Apple’s practice of charging for a privacy tool that, by its own admission, was not working as advertised.
Privacy has long been central to how Apple markets itself, especially as competitors have faced growing scrutiny over data practices. A flaw like this one, sitting unresolved for over a year after being reported, is the kind of thing that chips away at that reputation. Whether the lawsuit gains traction or not, the episode raises a fair question: if a paid privacy feature fails quietly for months, how would most users ever know?