Search Everything in One Place

Explore the web, images, videos, news, and more – all in one place.

News

Apple's privacy email feature was leaking your real address for over a year — here's what's still at risk

Apple Quietly Added a Clever Mail Setting That Fixes One of the Most Frustrating Inbox Issues
Apple patched a Hide My Email flaw that exposed real addresses via spam logs. But old server logs may still carry your data. What iCloud+ users should know.

Apple patched a Hide My Email flaw that exposed real addresses via spam logs. But old server logs may still carry your data. What iCloud+ users should know.

Apple fixed a bug in its Hide My Email service on July 3 that had been leaking users’ real email addresses to outside mail servers for over a year, the company confirmed to 404 Media.

The flaw went unfixed for more than 13 months after a security researcher first reported it to Apple in June 2025.

Hide My Email is part of the paid iCloud+ subscription. It generates disposable alias addresses so users can sign up for websites and services without revealing their actual inbox.

The feature costs money specifically because it promises that anonymity. During the period the bug was active, that promise did not hold.

How Addresses Got Exposed

When an email sent to a Hide My Email alias was automatically rejected as spam, the recipient’s real address showed up in the mail transfer logs generated by the sending server.

The sender did not need to do anything deliberate. A routine spam filter rejection was enough to trigger the leak.

Tyler Murphy, co-founder of EasyOptOuts, discovered the vulnerability and reported it to Apple. Apple told him in March 2026 that the problem had been resolved. It had not.

Murphy contacted 404 Media in early July after additional months had passed without a fix, and Apple patched the bug within days of the story going public.

Also: Apple came shockingly close to releasing its most powerful Mac ever, then decided almost nobody would ever buy it

Old Logs May Still Carry Exposed Addresses

Murphy and EasyOptOuts co-founder Ben Weiner issued a statement after the patch went live, warning that the fix does not eliminate all residual risk.

Mail transfer logs from servers that processed bounced messages before July 7, 2026, may still contain real email addresses tied to Hide My Email aliases.

Those logs are typically held by third-party mail providers, not Apple, and Apple has no way to delete them.

“We don’t know how often hidden email addresses were leaked in email logs,” Murphy and Weiner wrote. “For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn’t make it to your inbox, so you can’t review your spam folder to learn whether you were affected.”

Their recommendation is direct: anyone who created a Hide My Email alias before July 7, 2026 should assume that address may have been exposed at some point and could still appear in retained server logs held by outside parties.

Also: Apple quietly admitted AirPods were missing a long-overdue feature, and iOS 27 finally fixes it for newer models

Lawsuit Filed Over the Flaw

Apple is now facing a proposed class action lawsuit tied to the vulnerability. Filed earlier this month, the suit alleges Apple violated California’s false advertising law and related consumer protection statutes by selling Hide My Email as a privacy tool while the feature was not functioning as described.

Plaintiffs are seeking class action certification, which would allow the case to be brought on behalf of other iCloud+ subscribers affected during the exposure window.

The post Apple’s Privacy Email Feature Was Leaking Your Real Address for Over a Year — Here’s What’s Still at Risk appeared first on Gotechtor. Want more Apple coverage like this? Every Friday, we send the week's top 5 Apple stories — short, no fluff, free. Subscribe to the Gotechtor Weekly →

Read full story on Gotechtor

Related News

More stories you might be interested in.

Top