HackMyIP
← Back to News
2026-07-21 The Hacker News

Apple Patches Hide My Email Bug That Leaked Real Addresses in Mail Logs

PrivacyVulnerabilityCloud Security

Apple has resolved a critical privacy flaw in its Hide My Email service that silently exposed users' real email addresses in mail transfer logs, effectively defeating the feature's core privacy promise. The bug was disclosed to Apple by Tyler Murphy, co-founder of EasyOptOuts, on June 13, 2025, and a working patch was finally deployed on July 3, 2026, after two prior fix attempts in March and late June failed to fully close the gap.

Hide My Email, a paid iCloud+ feature launched in June 2021, generates unique, random forwarding addresses designed to mask a user's personal email from third-party senders and reduce spam. However, the flaw meant that simply sending a Hide My Email user a message that was automatically rejected as spam by the recipient's mail server caused the user's real email address to be written into email logs. "For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message," Murphy and co-founder Ben Weiner explained to 404 Media. Users who suspect their real address may have been captured in logs created before July 7, 2026, can use an email breach checker to monitor for unauthorized exposure of their personal address.

The incident is now at the center of a class action lawsuit accusing Apple of misleading customers about the privacy guarantees of Hide My Email while charging a subscription for it. The complaint alleges that Apple "has been fully aware of this problem for over a year" and "did not disable or pause Hide My Email, warn its customers of the flaw, or correct its privacy representations" during the extended remediation window. The case underscores how long disclosure-to-patch timelines can erode user trust, particularly when a product is explicitly marketed as a privacy safeguard.

For users concerned about email-level privacy, the episode is a reminder to regularly audit digital identities and reduce exposure surfaces. Running a privacy checkup can help identify over-shared personal details across accounts, while an DNS leak test can verify that other communications channels aren't inadvertently leaking metadata alongside email traffic. Although the bug is now patched, any Hide My Email aliases created before July 7, 2026, may still have traceable real-address data sitting in third-party mail server logs.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a VPN? →How websites track you →Browser fingerprinting explained →