Apple Finally Fixes Hide My Email Flaw After a Year of Inaction

Apple has fixed a Hide My Email vulnerability that could expose users’ real email addresses, but only after 404 Media published a report on July 1, 2026, more than a year after the initial discovery. A class action lawsuit was filed on July 16.

Tyler Murphy, co-founder of EasyOptOuts, discovered the vulnerability and reported it to Apple in June 2025, including instructions to replicate it. Apple acknowledged the report a month later and said it was investigating. What followed was a year of false starts, inaction, and Apple asking Murphy to stay quiet, culminating in public disclosure as the only option left to him.

Apple Finally Fixes Hide My Email Flaw After a Year of Inaction

What the Flaw Actually Did

Hide My Email is an iCloud+ feature that generates random alias addresses, forwarding mail to a user’s real inbox while keeping that address private. Murphy found a way to work backwards from an alias to the real address behind it, and in tests, the attack worked against 100% of Hide My Email addresses tested. 404 Media confirmed the issue using one of its own aliases.

The practical risk is worse than it might first appear. Murphy noted that people-search databases can tie an email address to a name, location, and other personal details. Anyone who adopted Hide My Email for personal safety, to avoid a stalker or an abusive contact, for example, was potentially more exposed than if they had never used the feature at all. Apple’s privacy marketing has leaned heavily on exactly this kind of protection.

Apple’s Response Timeline

The disclosure timeline is the damning part:

  • June 2025: Murphy reports the vulnerability to Apple with replication instructions.
  • July 2025: Apple acknowledges the report and says it is investigating.
  • March 2026: Apple tells Murphy it “addressed the reported issue in a recent system change.” Murphy tests it and finds it is not fixed. Apple says it is still investigating.
  • May 2026: Apple again asks Murphy not to disclose publicly while the inquiry continues. Apple says a fix is expected “in the coming weeks.”
  • July 1, 2026: After no fix materialises, Murphy goes public. 404 Media verifies the issue and publishes.
  • July 16, 2026: A proposed class action lawsuit is filed in California.

Murphy had also suggested Apple suspend the creation of new Hide My Email addresses as an interim step to limit customer exposure while the fix was developed. There is no indication Apple acted on that suggestion.

Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses.

That is what Murphy told 404 Media when he decided to go public. Given that Apple had told him in March that the issue was already fixed, and then confirmed in May that it was not, his decision to stop waiting is difficult to fault.

The Lawsuit and What It Claims

The proposed class action alleges Apple violated California’s false advertising law and other consumer protection statutes by knowingly offering a feature that does not work as advertised. The plaintiff’s argument is direct: Apple has known about the problem for over a year, it remains unfixed, and Apple continued to charge iCloud+ subscribers and market Hide My Email as genuine privacy protection throughout that period.

Whether the lawsuit succeeds depends heavily on what Apple knew and when, and how courts interpret the gap between “investigating” and knowingly misrepresenting the feature. Apple’s March claim that the issue had been addressed, followed by confirmation that it had not, is the kind of detail that tends to matter in these proceedings.

A Separate Problem: Domain Blocking

There is also a quieter issue with Hide My Email that this vulnerability has surfaced: Apple’s move of aliases to a dedicated private.icloud.com domain makes it straightforward for any platform that wants to block iCloud aliases to do so by domain. That is not a consequence of responsible disclosure, but it is a genuine setback for users who rely on the feature to get past sign-up walls.

The fix is now in, but it took public shaming via 404 Media and a class action filing to get there. That is not how responsible disclosure is supposed to work, and it is a harder problem for Apple’s privacy reputation to shake than any individual bug.

About the Author

Imran Hussain is the founder and editor of iThinkDifferent, which he launched in 2008 to cover Apple news, reviews, and how-to guides. He has spent over 15 years writing about iOS, macOS, and the wider Apple ecosystem, with a focus on hands-on guides - installing developer betas, troubleshooting, and walking through new features on his own devices. Based in Dubai, he also loves to cover photography, gaming, and the tech industry more broadly on his social media profiles.

Leave a comment