Apple’s Year-Long Delay in Patching Hide My Email Flaw Leaves Users Exposed

Apple patched a Hide My Email flaw that exposed real addresses after more than a year and public reporting by 404 Media. Researcher Tyler Murphy found 100% of tested aliases exploitable via email log leaks. A class-action lawsuit now claims deceptive marketing. Risks from pre-July 2026 logs remain. The episode highlights gaps in Apple's privacy tool response times.
Apple’s Year-Long Delay in Patching Hide My Email Flaw Leaves Users Exposed
Written by Ava Callegari

Apple knew about a serious vulnerability in its Hide My Email service for more than a year. The company only moved to fix it after independent outlet 404 Media published details in early July. The patch arrived on July 3. Yet questions linger about why such a basic privacy safeguard took so long.

Hide My Email forms a core part of the paid iCloud+ subscription. It generates random aliases that forward messages to a user’s real address. The point is simple. Keep your actual email out of the hands of marketers, spammers and trackers. But a flaw discovered by security researcher Tyler Murphy made that protection meaningless. Anyone who obtained one of those aliases could uncover the real email behind it.

Murphy, co-founder of EasyOptOut, first alerted Apple in June 2025. He provided replication steps. Company engineers acknowledged the report and said they were investigating. Months passed. In March 2026 Apple claimed a system change had resolved the matter. Murphy tested it. The vulnerability remained. He shared more data. Apple asked him to hold off on public disclosure while it continued its review. By late May the company told him a fix would come in the coming weeks. Nothing arrived.

Frustrated, Murphy reached out to 404 Media. The publication verified the issue with its own test account. It succeeded every time. “We don’t know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable,” Murphy told the outlet. He added that publicly accessible people-search sites make it easy to link an email address to other personal details. People relying on the feature for safety may be at risk.

The technical trigger involved sending a message to the alias that would be rejected as spam. That bounce revealed the real address in email logs. Such logs are often retained by mail servers. Even legitimate messages could trigger it under certain conditions. 404 Media chose not to publish the exact method while the bug was live. The goal was to avoid handing attackers a ready-made exploit.

But. The delay carried real consequences. Users who generated aliases before July 2026 may have already leaked their addresses into third-party logs. Murphy and EasyOptOut co-founder Ben Weiner issued a follow-up statement after the fix. “The bug that caused Apple’s Hide My Email to leak hidden email addresses to senders has been fixed,” they wrote. “However, we don’t think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we’d assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs.”

Apple confirmed the patch to 404 Media on July 21. It described the update as fully resolving the problem. No further details on the mechanism or scope were offered. The company had not responded to earlier requests for comment during the original reporting.

This episode fits a pattern. Apple markets privacy aggressively. Its advertising highlights how iCloud+ helps users avoid sharing real contact information. Sign in with Apple offers a limited version of the same relay capability. Both fell short here. A proposed class-action lawsuit filed July 15 in the U.S. District Court for the Northern District of California accuses the company of continuing to sell the service while aware of the defect. Plaintiff Anthony Alvarez claims he bought an iPhone and subscribed to a 200GB iCloud+ plan in March 2025. He says he would not have paid the same amount had he known the feature did not deliver the promised protection. The suit seeks refunds of subscription fees plus an injunction forcing Apple to repair the tool or disclose its limits clearly. It targets both full iCloud+ users and those who used the feature through new device purchases.

Coverage from TechCrunch on July 1 amplified the original findings. It noted Murphy had warned Apple more than a year earlier with no resolution. MacRumors reported similar details the same day. Later pieces in PCMag and iDrop News tracked the lawsuit. They highlighted that no known in-the-wild exploitation has occurred. The complaint rests on marketing claims rather than proven data breaches. Still, the legal action adds pressure. It argues Apple sold a privacy feature it could not actually provide.

Recent discussions on X reflect growing user skepticism. Posts from technology accounts on July 21 pointed to the 404 Media follow-up and questioned the company’s response speed. One thread from a cybersecurity-focused user noted that logs from the pre-patch period could surface in future incidents. Another highlighted the shift to a new domain for generated addresses. Apple plans to move from @icloud.com to @private.icloud.com. That change, announced in June, may help services block relay emails more easily. It does nothing to address the underlying leak.

Industry observers point to the human and technical costs. Murphy’s persistence forced the issue into the open. Without his decision to go public the flaw might have persisted longer. Apple security teams receive thousands of reports annually. Prioritization decisions matter. A privacy tool positioned as a selling point for paid subscriptions arguably deserved faster treatment. The fact that a simple bounce could expose the real address suggests the relay system tied identities too loosely somewhere in the forwarding pipeline.

Users cannot easily audit whether their aliases were compromised. Many bounced messages never reach an inbox. They vanish into spam filters or server logs. That opacity leaves individuals in the dark. Those who used Hide My Email to register for sensitive services or to shield themselves from harassment now face uncertainty. The real email might already sit in a database somewhere. Or it might not. There is no definitive way to know.

Apple has a strong record on patching vulnerabilities once they reach public attention. This case stands out because the company had internal knowledge for so long. Its statements to Murphy evolved from investigation to claimed resolution to continued study. Only after media scrutiny did the patch deploy. That sequence raises uncomfortable questions about accountability in consumer privacy tools.

The fix itself appears effective. Tests after July 3 no longer succeed. Yet the lingering risk from historical logs means the story does not end neatly. Companies that received bounces before the patch could still hold the data. People-search aggregators might already link those addresses to names and profiles. The privacy expectation customers paid for has been retroactively undermined.

Legal experts following the class action predict it will test the boundaries of false-advertising claims tied to software features. Courts have sometimes sided with consumers when premium services fail to meet documented promises. Apple will likely argue that the feature performed as intended in normal use and that the flaw was an edge case. Plaintiffs counter that any exposure defeats the entire purpose. The case could drag on for months or years. In the meantime users must decide whether to continue trusting the service or seek alternatives.

Alternatives exist. Services such as SimpleLogin and Firefox Relay offer similar forwarding with their own privacy models. Some integrate directly with password managers. None match Apple’s tight hardware integration or the automatic generation during Sign in with Apple flows. That convenience helped drive adoption. It also concentrated risk. When one vendor controls the relay for millions the impact of a single bug multiplies.

Security researchers continue to probe Apple’s privacy stack. Past discoveries around iCloud Private Relay and other features have prompted quicker fixes. The extended timeline here may reflect internal debate over the complexity of the relay infrastructure or simple resource allocation. Whatever the reason the outcome feels at odds with the company’s public stance on user data protection.

Going forward Apple could improve transparency. Clear statements on bug timelines and affected users would help. So would tools allowing customers to review or rotate compromised aliases. For now the patched system offers better protection than it did in June. The trust deficit created by the delay will take longer to repair.

Subscribe for Updates

CloudSecurityUpdate Newsletter

The CloudSecurityUpdate Email Newsletter is essential for IT, security, and cloud professionals focused on protecting cloud environments. Perfect for leaders managing cloud security in a rapidly evolving landscape.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us