As far back as June 2025, security researcher Tyler Murphy discovered a flaw in the Hide My Email feature offered through Apple’s iCloud+ subscription.
The irony was considerable. A function designed to shield a user’s genuine mailbox address from disclosure could instead be exploited by attackers or advertising firms to obtain precisely that address.
Murphy reported the flaw to Apple‘s security team immediately. The company did investigate and issued a fix intended to stop real addresses from leaking. Upon verification, however, the researcher found the remedy incomplete. The vulnerability still yielded users’ true email addresses.
Apple Responds Again: This Time It Is Genuinely Fixed
Addressing the researcher’s assertion that the flaw remained unresolved, Apple has now issued a further statement. The team deployed a dedicated patch for the issue on 3 July 2026, and the company maintains that this patch resolves the problem entirely.
Whether the repair truly holds may still require independent verification. Apple confirmed the fix to 404 Media, the outlet whose coverage preceded the patch. One hopes this time the matter is genuinely settled, with no residual issues left behind.
How Hide My Email Works
The mechanism behind the feature is not especially complicated. Apple generates multiple random mailbox addresses for a user through its own mail servers.
Each of these addresses automatically forwards incoming messages to the user’s real inbox. When registering for various accounts, a person can supply the random address instead.
Leakage of a random address therefore matters little. Should spam begin arriving, the user can simply retire that particular alias at any moment.
Working Alongside Sign in with Apple
The feature serves equally well on its own or in concert with Apple’s sign-in system. Some applications and websites offer rapid login through an Apple account.
During that process, a user may elect to employ the hidden email option. Apple then creates a random address on their behalf automatically. Used frequently, the feature genuinely does spare a real inbox from a bombardment of advertising mail.
What Users Should Consider Now
A patched flaw does not undo past exposure. Addresses revealed while the vulnerability remained open may already sit in third-party records.
Anyone who relied heavily on the feature might therefore review which aliases they created and when. Retiring older aliases and generating fresh ones costs little and removes lingering doubt.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.