Apple has patched a vulnerability in its iCloud+’s Hide My Email feature that allowed hidden email addresses to be easily accessed, according to a report from 404 Media. The publication first disclosed the issue in early July and noted that Apple had been aware of it for at least a year prior. The Hide My Email feature was introduced by Apple in 2021 to create dummy email addresses for enhanced privacy.
Apple stated that a software patch was deployed on July 3, successfully resolving the vulnerability. Prior to the patch, users’ hidden email addresses could be revealed by sending messages to the obscured address that were marked as spam. Tyler Murphy, co-founder of EasyOptOuts, who initially reported the vulnerability, expressed concerns that risks to users remain.
Murphy said, “The bug that caused Apple’s Hide My Email to leak hidden email addresses to senders has been fixed. However, we don’t think the risk to Hide My Email users has been eliminated.” He highlighted that non-malicious emails could still reveal hidden addresses and noted that mail transfer logs are often retained, suggesting that addresses created before July 7, 2026, might be exposed in third-party logs.
Murphy first alerted Apple to the flaw in June 2025. After several months of investigation by Apple, he continued to find instances of hidden email addresses being exposed. Following Apple’s promise to address the issue but no satisfactory resolution, Murphy contacted 404 Media to disclose his findings.
The vulnerability threatens to undermine Apple’s public image, which is heavily centered on privacy commitments. Moreover, PCMag reported that Apple now faces a proposed class action lawsuit related to the Hide My Email vulnerability. The lawsuit seeks an injunction against what it terms Apple’s deceptive conduct and a full recovery of subscription fees paid for the feature.





