Apple Patches Hide My Email Flaw After Class Action Lawsuit

Apple has deployed a server-side fix for a Hide My Email flaw after a class action lawsuit accused the company of misleading customers.

By Central
The vulnerability allowed attackers to learn users' real email addresses through bounced spam messages.
Highlights
  • The vulnerability allowed an attacker to learn a user's real email address via bounced spam messages.
  • Apple was aware of the flaw for over a year before deploying the server-side fix.
  • A class action lawsuit was filed by California resident Anthony Alvarez over the privacy breach.

Apple has deployed a server-side fix for a vulnerability in its iCloud+ Hide My Email service that could expose users’ real email addresses, a patch that arrives more than a year after the issue was first reported and only weeks after a proposed class-action lawsuit accused the company of misleading customers about the feature’s privacy guarantees. The flaw, discovered by privacy researcher Tyler Murphy in June 2025, allowed an attacker to learn a user’s real email address by sending a message that triggered a spam rejection on the recipient’s mail server. Apple confirmed to 404 Media that the fix went live on July 3, 2026.

How the Hide My Email Vulnerability Worked

The weakness resided in the way Hide My Email handles bounced messages. When a user signed up for a service using a random iCloud+ alias, any email sent to that alias would normally be forwarded anonymously to the user’s real inbox. However, Murphy found that if the recipient’s email infrastructure automatically rejected an incoming message as spam, the sender could receive a non-delivery report that contained the user’s actual email address instead of the anonymized alias. This defeated the core purpose of the feature, which is to shield personal email addresses from third parties.

Murphy disclosed the vulnerability to Apple through its responsible disclosure program in June 2025. Apple investigated the report over the following year and at one point believed the issue was resolved, but Murphy determined the fix was incomplete and the flaw remained exploitable. After repeated attempts to secure a permanent patch, he contacted 404 Media, which published an initial report while withholding technical details until Apple could deploy a solution.

What Is Hide My Email and Why Does This Matter?

Hide My Email, introduced in 2021 as part of the iCloud+ subscription, lets users generate unique, random email aliases when signing up for websites, apps, or online services. Messages sent to these aliases are forwarded to the user’s primary inbox without revealing the underlying address. The feature is designed to reduce spam, limit cross-site tracking, and give users control over who can contact them. The vulnerability directly undermined that promise by potentially leaking the real address during routine email delivery failures.

Class Action Lawsuit Follows Public Disclosure

The patch comes just days after California resident Anthony Alvarez filed a proposed class-action lawsuit against Apple in the U.S. District Court for the Northern District of California. The complaint alleges that Apple continued to market Hide My Email as a robust privacy feature despite having known about the vulnerability for more than a year. The lawsuit seeks reimbursement of iCloud+ subscription fees attributed to the feature and an injunction against what it describes as deceptive business practices.

Limitations of the Patch and Remaining Risks

Murphy has warned that the fix does not eliminate all risk for users who created aliases before the patch was applied. Mail transfer logs are commonly retained by email providers, meaning that real email addresses exposed during spam rejections prior to July 3, 2026, could still be stored in third-party systems. As a precaution, he recommends assuming that any Hide My Email alias created before July 7, 2026, may have been exposed if it ever received a message that was automatically rejected as spam.

Broader Privacy Context for Hide My Email Users

Earlier this year, court documents revealed that Apple can identify the account behind a Hide My Email alias when presented with a lawful request, following the company’s provision of subscriber information to the FBI during a criminal investigation. That case underscored that the feature is designed to conceal users’ email addresses from third parties, not from Apple itself or law enforcement acting under valid legal process. Separately, Apple recently announced that newly generated aliases will use the @private.icloud.com domain instead of @icloud.com, a change intended to consolidate relay services but one that privacy advocates say could make anonymous addresses easier for websites to identify and block.

What Affected Users Should Do Now

Anyone who relies on Hide My Email should take immediate steps to protect their privacy. First, ensure that all current aliases were created after Apple’s July 3, 2026 fix. For sensitive accounts such as banking, healthcare, or primary communication services, consider replacing any alias created before July 7, 2026, with a newly generated one. Monitor linked email accounts for unexpected bounce messages or signs of exposure, and enable two-factor authentication on any service where an alias may have been compromised. For users seeking stronger anonymity, using a reputable privacy-focused email relay service or a dedicated anonymous email provider offers an additional layer of protection beyond what native platform features can guarantee.

Share This Article