Breaking
ARإنقاذ 10 أشخاص إثر هبوط اضطراري لطائرة مائية في نيويوركUKSuper Typhoon Bavi Approaches Guam and Northern Mariana Islands with Catastrophic WindsRUВодитель Mercedes, сбивший мать с детьми в Калининграде, задержанFRPyrénées-Orientales : 10 000 personnes évacuées face à un incendie "gigantesque"CN超級颱風巴威逼近美屬羅塔島 關島北馬里亞納群島遭強風豪雨侵襲VNKia Việt Nam tung ưu đãi tháng 7, Carnival giảm tới 70 triệu đồngKR신세계 하이퍼그라운드, 태국 센트럴백화점에서 K브랜드 팝업 행사 개최DETrump soll Fifa-Chef wegen Balogun-Sperre angerufen habenINTLFights, Fireworks Thrown at Police in Chaotic Fourth of July Celebration in Newport BeachKR'스벅 사태' 이어 또 갈라진 사회…학교 앞엔 근조·응원 화환 나란히ARإنقاذ 10 أشخاص إثر هبوط اضطراري لطائرة مائية في نيويوركUKSuper Typhoon Bavi Approaches Guam and Northern Mariana Islands with Catastrophic WindsRUВодитель Mercedes, сбивший мать с детьми в Калининграде, задержанFRPyrénées-Orientales : 10 000 personnes évacuées face à un incendie "gigantesque"CN超級颱風巴威逼近美屬羅塔島 關島北馬里亞納群島遭強風豪雨侵襲VNKia Việt Nam tung ưu đãi tháng 7, Carnival giảm tới 70 triệu đồngKR신세계 하이퍼그라운드, 태국 센트럴백화점에서 K브랜드 팝업 행사 개최DETrump soll Fifa-Chef wegen Balogun-Sperre angerufen habenINTLFights, Fireworks Thrown at Police in Chaotic Fourth of July Celebration in Newport BeachKR'스벅 사태' 이어 또 갈라진 사회…학교 앞엔 근조·응원 화환 나란히
Newsgather
BackVulnerability in Apple's Hide My Email Feature Could Expose User Emails
Vulnerability in Apple's Hide My Email Feature Could Expose User Emails
Developing
Engadget4d agoTech1 min read

Vulnerability in Apple's Hide My Email Feature Could Expose User Emails

Quick Look

  • A vulnerability in Apple's Hide My Email feature, part of iCloud+, may allow hackers to link users' real email addresses to the anonymous ones created by the service.
  • Researchers reported the issue to Apple a year ago, but it remains unpatched.

AI-generated summary

Why It Matters

Apple's Hide My Email feature allows iCloud+ subscribers to create anonymous email addresses to protect their privacy. A vulnerability reportedly allows hackers to link these anonymous emails back to users' real ones.

Font size

Hide My Email may not be keeping your personal information fully private. This feature is an option iCloud+ subscribers can use to create an anonymous email address rather than using their own contact info. It's used as a workaround to avoid spam and data trackers, or simply to keep personal information safe against potential future data breaches. However, according to a report by 404 Media, there is a vulnerability with this feature that allows hackers to connect users' real email contacts to the ones created by Apple.

We've reached out to Apple for comment, and will update this article if we hear back.

The issue was uncovered by the team at EasyOptOuts, and according to CEO Tyler Murphy, the group contacted Apple about the issue and how to replicate it a year ago. He had some conversation with the company via email and Apple reportedly responded at various points that it was looking into the problem or that a solution was either in the works or had been deployed. However, Murphy and 404 reporter Joseph Cox were able to exploit the vulnerability for this article. The exact details of the exploit have not been disclosed due to the potential risk to Apple users.

"We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer. Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses," Murphy told 404. He added, "We don't know the full scope of the issue, but in our limited tests with volunteers, 100 percent of Hide My Email addresses were exploitable."

What to Watch

AI outlook — possibilities, not facts

  • Apple will likely release a patch to fix the Hide My Email vulnerability.

    Likely · Within weeks

Open Questions

  • What is the exact technical detail of the exploit?
  • Has any user's email been compromised due to this vulnerability?
  • Why has Apple not fixed this issue after a year?

Related Topics

This article was originally published by Engadget.

Related Stories

More on this topicApple