Apple fixed a bug in its Hide My Email service on July 3 that had been leaking users’ real email addresses to outside mail servers for over a year, the company confirmed to 404 Media.
The flaw went unfixed for more than 13 months after a security researcher first reported it to Apple in June 2025.
Hide My Email is part of the paid iCloud+ subscription. It generates disposable alias addresses so users can sign up for websites and services without revealing their actual inbox.
The feature costs money specifically because it promises that anonymity. During the period the bug was active, that promise did not hold.
How Addresses Got Exposed
When an email sent to a Hide My Email alias was automatically rejected as spam, the recipient’s real address showed up in the mail transfer logs generated by the sending server.
The sender did not need to do anything deliberate. A routine spam filter rejection was enough to trigger the leak.
Tyler Murphy, co-founder of EasyOptOuts, discovered the vulnerability and reported it to Apple. Apple told him in March 2026 that the problem had been resolved. It had not.
Murphy contacted 404 Media in early July after additional months had passed without a fix, and Apple patched the bug within days of the story going public.
Old Logs May Still Carry Exposed Addresses
Murphy and EasyOptOuts co-founder Ben Weiner issued a statement after the patch went live, warning that the fix does not eliminate all residual risk.
Mail transfer logs from servers that processed bounced messages before July 7, 2026, may still contain real email addresses tied to Hide My Email aliases.
Those logs are typically held by third-party mail providers, not Apple, and Apple has no way to delete them.
“We don’t know how often hidden email addresses were leaked in email logs,” Murphy and Weiner wrote. “For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn’t make it to your inbox, so you can’t review your spam folder to learn whether you were affected.”
Their recommendation is direct: anyone who created a Hide My Email alias before July 7, 2026 should assume that address may have been exposed at some point and could still appear in retained server logs held by outside parties.
Lawsuit Filed Over the Flaw
Apple is now facing a proposed class action lawsuit tied to the vulnerability. Filed earlier this month, the suit alleges Apple violated California’s false advertising law and related consumer protection statutes by selling Hide My Email as a privacy tool while the feature was not functioning as described.
Plaintiffs are seeking class action certification, which would allow the case to be brought on behalf of other iCloud+ subscribers affected during the exposure window.