news.mlab.sh
Back to the feed
threat-intel

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Medium
Summary

Apple has finally fixed a significant security flaw in its Hide My Email service, which allowed real email addresses to be exposed in mail logs. The issue stemmed from sending a rejected spam email to a Hide My Email user, revealing their actual email address. This follows a year-long delay in addressing the problem and a related class action lawsuit alleging misleading privacy claims.

Apple has released a fix for a security vulnerability in its Hide My Email service. The flaw, disclosed by Tyler Murphy and EasyOptOuts in June 2025, enabled users’ real email addresses to be revealed in email logs. Hide My Email generates unique, random email addresses that forward messages to a user’s personal email inbox. The service requires a paid iCloud+ subscription and was initially announced in June 2021.

However, a targeted message that was automatically rejected as spam would expose a user’s actual email address. Despite being aware of the issue for over a year, Apple failed to address it, nor did they disable the service or warn users.

404 Media reported that the fix was deployed on July 3, 2026, following unsuccessful attempts to patch the issue in March and again on June 30, 2026. The development comes as Apple is currently facing a class action lawsuit alleging misleading privacy claims related to Hide My Email and its associated pricing.

“We don’t know how often hidden email addresses were leaked in email logs,” stated Murphy and EasyOptOuts co-founder Ben Weiner. “For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message.” It’s possible that email addresses linked to Hide My Email addresses created before July 7, 2026, may have been captured in mail transfer logs.

This incident highlights concerns about Apple’s privacy practices and the potential for vulnerabilities in features marketed as privacy-enhancing.

Read the full article at The Hacker News