Apple Patches Year-Old Hide My Email Bug That Leaked Real Addresses

A flaw in Apple's email-cloaking feature let real addresses appear in mail logs. The fix took over a year to ship.

ThreatVectr Newsdesk· 3 min read
Photoreal editorial shot of a modern smartphone screen showing a generic mail app inbox with a blurred alias-style email address at the top, sitting on a matte
Share

Key points

  • Apple fixed a flaw in Hide My Email, its service that hides a user's real email address behind a random alias, on July 3, 2026.
  • The bug let real email addresses appear in mail server logs, defeating the whole point of the feature.
  • Tyler Murphy, co-founder of the data-removal firm EasyOptOuts, reported the issue to Apple over a year before it was patched.
  • The problem was first reported by 404 Media on Tuesday.
  • No public evidence yet that anyone abused the flaw to unmask users at scale.

Apple has quietly closed a hole in Hide My Email, the privacy feature that gives users a random throwaway address so they never have to hand over their real one.

The flaw did the opposite of what the feature promises. Under certain conditions, the user's true email address ended up visible in mail server logs, meaning the companies and services receiving those messages could see who the person really was.

Apple shipped the fix on July 3, 2026. The researcher who reported it, Tyler Murphy, co-founder of EasyOptOuts (a service that removes personal data from broker sites), had flagged the problem to Apple more than a year earlier. The delay was first reported by 404 Media.

What is Hide My Email supposed to do?

It is meant to keep your real email address secret. When you sign up for a newsletter or a shopping site, Apple gives you a random alias like fuzzy.otter.4821@icloud.com. Mail sent to that alias is forwarded to your real inbox. The sender never sees your actual address.

That matters for two reasons. It cuts down on spam, because you can burn any alias that starts getting abused. And it stops data brokers from linking your email to the rest of your online life.

The bug undermined both of those benefits. If your real address leaked into a company's mail logs, anyone with access to those logs (staff, contractors, or an attacker who broke in) could tie the alias back to you.

How did the leak happen?

Murphy found that the way Apple's relay servers handled certain message headers, the technical labels attached to every email, caused the underlying iCloud address to be written into logs on the receiving side. It was not a flashy remote exploit. It was a plumbing mistake in a privacy product, which is arguably worse.

Apple has not published a detailed advisory or a CVE identifier for the issue, which is a fair criticism given the feature's whole marketing pitch is privacy. The company confirmed the fix is now live for all users. Nothing on the user side needs to be updated. Existing aliases keep working.

Should ordinary users do anything?

Probably not, but a small check is worth your time. If you have used Hide My Email to sign up for services you would rather not be linked to your real Apple ID, keep an eye on whether those senders start hitting your primary inbox directly. That would be a sign your real address was captured somewhere along the way before the patch.

You can revoke and regenerate aliases from Settings on iPhone and iPad, or in System Settings on a Mac, under your Apple Account and then iCloud. It takes about ten seconds per alias.

The wider lesson is duller and more familiar. Privacy features are software, and software has bugs. A relay service is only as private as its worst logging path. Murphy sitting on a report for over a year while the leak continued is not a great look for Apple's vulnerability response process (this is the company that runs one of the better-funded bug bounty programs in the industry).

For now, the hole is closed. Whether anyone was quietly harvesting unmasked addresses from mail logs during those twelve-plus months is a question Apple has not answered.

© 2026 Threat Vectr