Apple Patches Hide My Email Bug Exposing Real Addresses in Mail Logs
Apple has fixed a year-old vulnerability in its Hide My Email service that could expose users' real email addresses in mail logs, a flaw that undermined the feature's core privacy promise.

Apple has finally addressed a significant privacy flaw within its Hide My Email service, which had the potential to reveal users' actual email addresses through mail logs. The vulnerability, disclosed over a year ago, directly contradicted the service's primary purpose of safeguarding user privacy by creating unique, random email addresses for communication.
The fix was quietly deployed by Apple on July 3, 2026, following a report from 404 Media. The Hide My Email feature, a component of the paid iCloud+ subscription announced in June 2021, generates disposable email addresses that forward messages to a user's personal inbox, aiming to reduce spam and protect user identity. However, the flaw meant that simply sending a targeted Hide My Email address a message that was automatically rejected as spam could cause the user's real email address to appear in the email logs.
This issue was first reported to Apple on June 13, 2025, by Tyler Murphy, co-founder of EasyOptOuts. Apple had previously attempted to patch the vulnerability in March and again on June 30, 2026, but these efforts were unsuccessful until the recent July deployment. While specific details were initially withheld to prevent exploitation, the resolution has allowed for more information to be shared.
According to Murphy and fellow EasyOptOuts co-founder Ben Weiner, the leak was triggered by routine spam rejections, even for legitimate messages. "We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can't review your spam folder to learn whether you were affected," they stated.
While the bug is now resolved, there remains a possibility that real email addresses associated with Hide My Email addresses created before July 7, 2026, may have been logged when non-malicious emails were bounced. Users who relied on the service for privacy before this date may need to be aware of this potential exposure.
The timing of this fix is particularly notable as Apple is currently facing a class-action lawsuit that accuses the company of misleading customers about the privacy protections offered by Hide My Email, especially given that it is a paid feature. The lawsuit alleges that Apple was aware of the problem for over a year but failed to act decisively.
Plaintiffs in the lawsuit claim that Apple did not disable or pause the Hide My Email service, nor did it warn customers or correct its privacy representations during the period the vulnerability was known. This inaction has led to significant user distrust and legal repercussions for the tech giant.
The resolution of this vulnerability is a critical step for Apple in restoring confidence in its privacy-focused services. It underscores the ongoing challenges in maintaining robust security for cloud-based features and the importance of prompt remediation when privacy-compromising flaws are discovered.