Apple has patched a flaw in its paid Hide My Email tool that was revealing subscribers’ actual inbox addresses for over a year. The company confirmed the deployment of a software patch on July 3 to fix a vulnerability in Hide My Email, an iCloud+ feature that creates anonymous email aliases for users signing up to websites and services without exposing their primary addresses.
The issue was first reported publicly in early July after 404 Media revealed that Apple had known about the flaw for more than a year. Security researcher Tyler Murphy, co-founder of EasyOptOuts, reported the bug to Apple in June 2025 and spent months working with the company as it investigated the problem.
Apple stated to 404 Media that the July 3 patch “has fully resolved the issue.” However, the disclosure comes amid a proposed class-action lawsuit alleging Apple continued marketing Hide My Email as a privacy feature despite its knowledge of the flaw.
Hide My Email generates random email addresses that forward messages to a user’s real inbox, reducing spam and limiting exposure of personal email addresses. Before the fix, carefully targeted emails rejected as spam could expose the recipient’s actual email address in mail server logs, undermining the feature’s core privacy objective.
Murphy and EasyOptOuts co-founder Ben Weiner warned that some privacy risks may persist, as email providers often retain historical mail logs. Although Apple claims the issue was fully resolved on July 3, AppleInsider reported that it was still able to reproduce the behavior on July 17 before later confirming it could no longer do so.
The publication noted that Apple has not explained whether the patch was rolled out in stages or why the vulnerability remained reproducible during testing. Both Murphy and Weiner later acknowledged that the underlying bug has been fixed but maintained that historical data retained in third-party mail logs could still pose a privacy concern for older aliases.
This incident underscores the challenges technology companies face when marketing privacy-focused services as paid products. Hide My Email’s value relies on keeping users’ real email addresses hidden. While there is no public evidence that the flaw was exploited on a large scale or that it exposed passwords or account access, the bug compromised a fundamental privacy guarantee of the feature.
The fix restores protection for users going forward. However, individuals who created Hide My Email aliases before early July 2026 may still need to consider that those addresses could exist in archived mail logs outside Apple’s control.




