{"id":62076,"date":"2026-07-04T17:47:51","date_gmt":"2026-07-04T21:47:51","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=62076"},"modified":"2026-07-04T17:47:51","modified_gmt":"2026-07-04T21:47:51","slug":"apple-hide-my-email-leak","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/apple-hide-my-email-leak\/","title":{"rendered":"Apple Hide My Email Leaks Users&#8217; Real Email Addresses"},"content":{"rendered":"<p>Apple&#8217;s Hide My Email tool, a flagship privacy feature designed to shield users&#8217; real email addresses when signing up for online services, contains a vulnerability that has allowed those addresses to be exposed for at least a year. Security researcher Tyler Murphy discovered the flaw in June 2025 and found that in tests with volunteers, 100% of Hide My Email addresses were exploitable. The revelation, which undermines the core promise of the feature, raises serious questions about the reliability of Apple&#8217;s privacy safeguards and the company&#8217;s responsiveness to security disclosures.<\/p>\n<h2>How the Hide My Email Vulnerability Exposes Real Addresses<\/h2>\n<p><a href=\"https:\/\/www.apple.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Apple<\/a> launched Hide My Email in 2021 as part of its iCloud+ subscription, generating unique, random email addresses that forward messages to a user&#8217;s personal inbox without revealing that underlying address. However, Murphy discovered that the system could be manipulated to link a newly created <strong>@icloud.com<\/strong> forwarding address back to the real email address of its creator. The exact technical details of the exploit remain undisclosed because the vulnerability has not yet been patched, but the implications are immediate: anyone using the feature for privacy-sensitive registrations may have had their true identity exposed.<\/p>\n<h2>Apple&#8217;s Response Timeline Raises Concerns<\/h2>\n<p>Murphy reported the problem to Apple in the summer of 2025 and was informed that the issue had been &#8220;addressed&#8221; by March 2026. However, when the researcher continued testing, the flaw remained exploitable. Apple later told Murphy that it was still investigating the issue, and the company did not respond to requests for comment when approached for this story. This delayed response, with the vulnerability persisting after a claimed fix, echoes a pattern that security researchers have criticized in the past, where bugs are acknowledged but not fully remediated in a timely manner.<\/p>\n<h2>What This Means for Apple Users and Online Privacy<\/h2>\n<p>The Hide My Email feature is widely used by privacy-conscious individuals who want to limit the amount of personal data they share with online services. A flaw that leaks the very email address the tool is supposed to conceal undermines that protection entirely. Users who rely on Hide My Email to avoid spam, data harvesting, or tracking should assume that any service they signed up for using the feature could potentially link that alias to their real address. This is especially concerning for journalists, activists, and anyone in high-risk situations who depend on Apple&#8217;s privacy tools as part of their operational security.<\/p>\n<h2>Other Security News This Week<\/h2>\n<p>Beyond the Apple vulnerability, several other stories shaped the security landscape. A member of the European Parliament&#8217;s PEGA Committee, which investigates spyware abuses, was himself targeted with <a href=\"https:\/\/overcentral.com\/en\/european-politician-hacked-pegasus-spyware\/\" title=\"European politician investigating spyware hacked with Pegasus\" data-iacss-internal=\"1\">Pegasus<\/a> malware. Meanwhile, top Google security staff warned that proposed EU competition rules could make Google Search and Android systems more vulnerable to hacking. In a separate incident, <a href=\"https:\/\/overcentral.com\/en\/meta-contractors-posed-as-teens\/\" title=\"Meta Contractors Posed as Teens to Test Rival Bots Suicide, Sex, Drugs\" data-iacss-internal=\"1\">Meta contractors posed<\/a> as teenagers to test how chatbots like Gemini and ChatGPT responded to high-risk topics, and a researcher used Anthropic&#8217;s Claude Opus 4.7 to break into the website of Front Gate, generating tickets for major US music festivals.<\/p>\n<p>Law enforcement also made progress against cybercrime: a 19-year-old Estonian-US dual citizen, Peter Stokes, was arrested in Finland and extradited to the US on charges linked to the <a href=\"https:\/\/overcentral.com\/en\/scattered-spider-guilty-tfl-attack\/\" title=\"Scattered Spider Hackers Plead Guilty in Transport for London Attack\" data-iacss-internal=\"1\">Scattered Spider<\/a> hacking group, which is believed to be composed of young English-speaking teenagers. In the messaging space, WhatsApp announced it will roll out usernames, allowing users to connect without sharing phone numbers, though Indian officials have opposed the move, citing fraud concerns. Finally, a review by the Institute for Justice found at least 24 cases where automatic license plate reader cameras produced false identifications, leading to innocent people being detained at gunpoint or jailed.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>If you use Apple&#8217;s Hide My Email feature, consider it compromised for any account where privacy matters. The most prudent step is to stop relying on the feature for new sign-ups until Apple confirms a complete fix and provides a clear explanation of what went wrong. For existing accounts created through Hide My Email, assume that the linked real address may be exposed and review your security posture accordingly. Use a reputable, zero-knowledge password manager to generate unique credentials for each service, enable two-factor authentication wherever possible, and monitor your primary email account for any signs of phishing or unauthorized access attempts. For high-sensitivity activities, consider using a dedicated, anonymous email service that has undergone independent security audits rather than relying on a single vendor&#8217;s privacy feature. The core lesson here is that no privacy tool is infallible, and layered protection remains the only reliable defense.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple&#8217;s Hide My Email tool, a flagship privacy feature designed to shield users&#8217; real email addresses when signing up for online services, contains a vulnerability that has allowed those addresses to be exposed for at least a year. Security researcher Tyler Murphy discovered the flaw in June 2025 and found that in tests with volunteers, [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":91181,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/62076.png","fifu_image_alt":"Apple Hide My Email Leaks Users' Real Email Addresses","footnotes":""},"categories":[349],"tags":[],"class_list":["post-62076","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/62076.png","fifu_image_alt":"Apple Hide My Email Leaks Users' Real Email Addresses","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62076","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=62076"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62076\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/91181"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=62076"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=62076"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=62076"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}