iOS 26

iPhone

iPad

Apple Watch

AirPods

Apple Deals

Apple’s Privacy Email Feature Was Leaking Your Real Address for Over a Year — Here’s What’s Still at Risk

Gotechtor select and review products independently. When you purchase through our links, we may earn a commission. See our ethics statement.

Apple fixed a bug in its Hide My Email service on July 3 that had been leaking users’ real email addresses to outside mail servers for over a year, the company confirmed to 404 Media.

The flaw went unfixed for more than 13 months after a security researcher first reported it to Apple in June 2025.

Hide My Email is part of the paid iCloud+ subscription. It generates disposable alias addresses so users can sign up for websites and services without revealing their actual inbox.

The feature costs money specifically because it promises that anonymity. During the period the bug was active, that promise did not hold.

How Addresses Got Exposed

When an email sent to a Hide My Email alias was automatically rejected as spam, the recipient’s real address showed up in the mail transfer logs generated by the sending server.

The sender did not need to do anything deliberate. A routine spam filter rejection was enough to trigger the leak.

Tyler Murphy, co-founder of EasyOptOuts, discovered the vulnerability and reported it to Apple. Apple told him in March 2026 that the problem had been resolved. It had not.

Murphy contacted 404 Media in early July after additional months had passed without a fix, and Apple patched the bug within days of the story going public.

Also: Apple came shockingly close to releasing its most powerful Mac ever, then decided almost nobody would ever buy it

Old Logs May Still Carry Exposed Addresses

Murphy and EasyOptOuts co-founder Ben Weiner issued a statement after the patch went live, warning that the fix does not eliminate all residual risk.

Mail transfer logs from servers that processed bounced messages before July 7, 2026, may still contain real email addresses tied to Hide My Email aliases.

Those logs are typically held by third-party mail providers, not Apple, and Apple has no way to delete them.

“We don’t know how often hidden email addresses were leaked in email logs,” Murphy and Weiner wrote. “For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn’t make it to your inbox, so you can’t review your spam folder to learn whether you were affected.”

Their recommendation is direct: anyone who created a Hide My Email alias before July 7, 2026 should assume that address may have been exposed at some point and could still appear in retained server logs held by outside parties.

Also: Apple quietly admitted AirPods were missing a long-overdue feature, and iOS 27 finally fixes it for newer models

Lawsuit Filed Over the Flaw

Apple is now facing a proposed class action lawsuit tied to the vulnerability. Filed earlier this month, the suit alleges Apple violated California’s false advertising law and related consumer protection statutes by selling Hide My Email as a privacy tool while the feature was not functioning as described.

Plaintiffs are seeking class action certification, which would allow the case to be brought on behalf of other iCloud+ subscribers affected during the exposure window.

🍎 The only 5 Apple stories that matter — sent every Friday to 50K+ smart readers. You in?

Founder & Editor-in-Chief

Herby has a healthy obsession with all things Apple, especially the iPhone. He loves to rip things apart to see how they work. He is responsible for the editorial direction, strategy, and growth of Gotechtor.

Herby Jasmin

's latest stories

Leave a Comment

Be kind. Discriminatory language, personal attacks, promotion, and spam will be removed. Please read Gotechtor's Community Guidelines before participating.