Apple has patched a vulnerability in its iCloud+’s Hide My Email feature that allowed hidden email addresses to be accessed easily, according to a report by 404 Media. The issue was first reported by 404 Media in early July 2023, with indications that Apple had been aware of it for at least a year prior to the publication.

Apple stated that it deployed a software patch on July 3, 2023, which addressed the vulnerability completely. Before this patch, users’ actual email addresses could be revealed if a message sent to a Hide My Email address was flagged as spam. Tyler Murphy, co-founder of EasyOptOuts, was the individual who alerted 404 Media about the vulnerability.

Despite the patch, Murphy raised concerns that iCloud+ users may not be fully protected. Murphy noted, “The bug that caused Apple’s Hide My Email to leak hidden email addresses to senders has been fixed. However, we don’t think the risk to Hide My Email users has been eliminated.” He emphasized that non-malicious emails bouncing could still expose hidden addresses and that mail transfer logs might retain this information.

Additionally, Murphy warned that any hidden email addresses linked to a Hide My Email account created before July 7, 2026, could have been exposed. He informed Apple of the issue in June 2025, and after several months of investigation, the company claimed to have resolved it. However, upon still discovering hidden email addresses after the fix, Murphy prompted Apple to reassess the issue.

With Apple’s slow response to the reported vulnerability, Murphy reached out to 404 Media to disclose his findings. Apple’s reputation for privacy has been a significant aspect of its public image, making this vulnerability a concern. A proposed class action lawsuit has been filed against Apple, seeking an injunction and refund of subscription fees for customers affected by the Hide My Email vulnerability.


Featured image credit