Apple Patches iCloud+ Hide My Email Vulnerability, Expert Warns of Lingering Risk
Quick Look
- Apple has patched a vulnerability in its iCloud+ Hide My Email feature that could expose users' real email addresses, 404 Media reports.
- While Apple deployed a fix on July 3, co-founder of EasyOptOuts, Tyler Murphy, warns that emails linked to Hide My Email addresses created before July 7, 2026, may still be exposed in third-party logs.
AI-generated summary
Why It Matters
Apple introduced Hide My Email in 2021 as an iCloud+ feature to generate dummy email addresses for enhanced user privacy. The vulnerability, which allowed exposure of real email addresses, was known to Apple for at least a year before the patch.
Apple has patched a vulnerability in iCloud+'s Hide My Email feature that made it possible to easily view the email addresses the service is designed to obscure, 404 Media reports. The publication first reported on the vulnerability in early July and revealed that Apple had been aware of the issue for at least a year. The company originally introduced Hide My Email as a way to generate dummy email addresses for added privacy in 2021.
According to 404, Apple says it deployed a software patch on July 3 that completely resolved the vulnerability. Before the company's patch, it was reportedly possible to reveal an iCloud+ user's email by sending a message to their Hide My Email-obscured address that's rejected as spam. While that's no longer possible, Tyler Murphy, co-founder of EasyOptOuts and the person who originally made 404 aware of the vulnerability, doesn't think iCloud+ users' emails are completely safe.
"The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. However, we don't think the risk to Hide My Email users has been eliminated," Murphy said. "Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs."
Engadget has contacted Apple to comment on the Hide My Email vulnerability. We'll update this article if we hear back.
Murphy reportedly told Apple about this Hide My Email issue in June 2025. Over several months, the company looked into the vulnerability and claimed to fix it. After he was still able to find hidden email addresses, Apple again told Murphy it would look into the issue. In case the company decided to leave the vulnerability unpatched, Murphy then contacted 404 with what he discovered.
What to Watch
AI outlook — possibilities, not facts
Engadget will update the article if Apple provides a comment on the Hide My Email vulnerability.
Likely · Within days
Open Questions
- Will Apple provide further comment on the ongoing risks to Hide My Email users?
- What is the extent of past email exposure due to the vulnerability?






