APPLE'S HIDE MY EMAIL LEAKS REAL ADDRESSES!
A privacy bug Apple has known about for a year still exposes iCloud+ subscribers' personal email addresses.
by editor6 min readcomments soon

Apple's Hide My Email feature, sold as a privacy tool for iCloud+ subscribers, has a vulnerability that can reveal the very email addresses it is supposed to conceal. The bug has been active for more than a year, and Apple has known about it for that entire period without issuing a fix.
The vulnerability was discovered and reported to Apple by Tyler Murphy, co-founder of the privacy company EasyOptOuts, in June 2025. Apple acknowledged the report a month later and said it was investigating. In March 2026, the company told Murphy the issue had been addressed in an update. But when Murphy tested again, the problem remained. He provided Apple with more information. As recently as May 2026, Apple said it was still investigating and asked him not to go public, promising a fix "in the coming weeks" that has not materialised.
Murphy decided to go public anyway. "We reported the issue and replication instructions to Apple over a year ago. We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer. Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses."
WHAT THE BUG IS
Hide My Email lets iCloud+ subscribers generate random email addresses at the icloud.com domain. When a user signs up for a service with one of these aliases, email is forwarded to their real inbox without the recipient ever seeing the underlying Apple ID. It is a useful tool for avoiding spam and preventing data brokers from linking activity across accounts.
But the bug allows anyone to reverse that mapping. Given a Hide My Email address, an attacker can discover the real email address it forwards to. 404 Media independently verified the issue by generating a fresh Hide My Email address and sending it to Murphy. Within five minutes, Murphy returned the real Apple ID email associated with that account. In Murphy's limited testing, every single Hide My Email address he tried was exploitable: a 100% hit rate.
The outlet has not published technical details of the exploit because the vulnerability remains live, and doing so would put users at risk. But the fact that it works quickly, silently, and without any apparent rate-limiting makes it a serious privacy failure.
THE TIMELINE IS THE MOST DAMNING PART
June 2025: report. July 2025: Apple acknowledges. March 2026: Apple says it is fixed. It is not. May 2026: Apple admits it is still investigating, asks for patience, promises a fix in weeks. As of publication, the vulnerability is still present.
Murphy gave Apple more than enough time and even re-reported after the mistaken fix claim. The request not to go public is standard in responsible disclosure, but at some point the burden shifts to the company to either patch or explain why it cannot. A year with no fix, especially for a bug that completely undermines the feature's stated purpose, is hard to justify.
The episode reveals a broader pattern. Apple markets itself as a privacy-first company, and iCloud+ is a paid service that costs between $0.99 and $9.99 per month depending on the storage tier. Customers pay for a promise that the company has been unable to keep.
THE OTHER SHOE
Separately, a report from June 2026 revealed Apple's plan to move Hide My Email addresses from the icloud.com domain to private.icloud.com. The intent, according to the coverage, is to prevent websites from easily identifying and blocking throwaway email addresses. Currently, many services already treat any address at icloud.com as disposable and refuse to accept it. A new dedicated domain would make that blocking even easier, since it would be trivial to flag every @private.icloud.com address.
That change would effectively neuter the feature's biggest practical use: signing up for services that are hostile to alias emails. Users who rely on Hide My Email to avoid spam, tracking, or forced account creation would find that their aliases are rejected at the registration screen. The feature would still protect against accidental exposure to a single human recipient, but its broader utility would collapse.
The domain shift is a separate decision from the vulnerability, but they compound each other. One actively leaks your real address. The other makes the feature easier for merchants to block. Together, they suggest a feature that Apple is either unwilling to fix or actively deprioritising.
CURRENTLY, THERE IS NOTHING YOU CAN DO
There is no workaround from the user side. The vulnerability is server-side, meaning it does not matter how carefully you generate or use your Hide My Email addresses. Anyone who obtains one of your aliases can potentially unmask you.
The only protective step is to stop using Hide My Email entirely until Apple confirms the bug is fixed. That is a painful recommendation for people who have built their account management around the feature, but the risk is real. Data brokers and people-search websites can take an email address and return your name, location, phone number, and social media profiles. An exposed real email from an alias designed to protect your identity can undo years of careful compartmentalisation.
THE WILL FIX IT EVENTUALLY, I GUESS
Apple is likely to fix the vulnerability eventually, but the delay raises questions about its internal vulnerability management. A bug this fundamental to a paid privacy service should have been treated as critical. Instead, it languished for a year.
The domain change to private.icloud.com may still go ahead, but if Apple wants to retain user trust, it should reconsider or at least offer a way for users to keep the old domain. Otherwise, the feature becomes a honeypot: you sign up thinking you are protected, but your real email is either exposed by the bug or your alias is rejected by the site you are trying to use.
Murphy's decision to go public was the right call. Users deserve to know when a paid privacy product is not delivering on its promise. Apple has had a year to fix this. Now the rest of us get to see how it responds.
what did you make of it?
more from consumer tech
consumer tech
GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCH
Starting this week, US users can ask AI Mode to make a playlist, fill a grocery cart, or design a flyer without leaving the search…
consumer tech
ONEPLUS DEAD IN THE WEST, OPPO OVERLORDS PULL PLUG
The brand that built its reputation on has settled for leaving its biggest markets. Existing phones still work. New ones won't come.
consumer tech
GOOGLE PIXEL 10 PRO DROPS TO 699, BEST DEAL YET!
A $300 discount on the 128GB model undercuts Prime Day pricing and signals a clear runway to the pixel 11 launch.
consumer tech
APPLE RAISES APPLE ON BUNDLE FOR FAMILY AND PERMIER PLANS
the Family plan jumps $2 to $27.95 a month and the Premier to $39.95; Apple hasn’t explained the bundle increase beyond citing music licensing for…





