A vulnerability in Apple's 'Hide My Email' feature, part of iCloud+, exposed real email addresses to potential exploitation. Despite being reported in mid-2025, the flaw remained open for over a year before Apple addressed it.
Tyler Murphy, co-founder of EasyOptOuts, uncovered the defect. After reporting it to Apple, responses were minimal until 404 Media's report gained traction, leading to fixing the issue. The vulnerability allowed users to unmask real emails by sending targeted spam.
The flaw compromised user trust in Apple’s privacy commitments, prompting a class action lawsuit. Apple claimed to have fixed the issue after the media's coverage and lawsuit pressures in July 2026. However, this incident has raised questions about Apple's delay in securing user data.
Apple asserts the vulnerability, patched on July 3, 2026, no longer poses a threat. While the patch is said to fully resolve the issue, privacy advocates remain cautious about ongoing data protection in iCloud+ and similar services.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Apple has patched a vulnerability in its iCloud+ Hide My Email feature that allowed hidden addresses to be accessed. The patch was deployed on July 3, 2023, after being reported in July and recognized by Apple for over a year, raising concerns about data privacy and user safety.
Apple has fixed a security flaw in its Hide My Email service that unmasked users' real email addresses. This bug, which persisted for over a year, compromised user privacy and is significant as users pay for iCloud+ services to safeguard their emails.
Apple has fixed a vulnerability in the iCloud+ 'Hide My Email' feature that exposed users' real email addresses. The bug, reported in June 2025, could have allowed unauthorized access to personal email information, prompting security concerns and a proposed lawsuit.
Apple has patched a vulnerability in its Hide My Email feature that allowed users' real email addresses to be exposed. The issue was known for over a year but only addressed following media coverage and a class action lawsuit against Apple.
A class action lawsuit has been filed against Apple, claiming the company misled users regarding the privacy protections of its Hide My Email feature. The lawsuit alleges that Apple failed to address a known flaw that could expose users' real email addresses for over a year, raising concerns about the company's privacy commitments.
Apple's Hide My Email feature has a vulnerability that allows users' real email addresses to be exposed easily. This flaw has been known to Apple for over a year but remains unaddressed, raising serious concerns about user data privacy for its one billion paid subscribers.
A reported vulnerability in Apple's Hide My Email feature can link real email addresses with generated anonymous ones. This flaw poses significant privacy risks for users who rely on the service to maintain anonymity and protect against spam and data tracking.
A bug in Apple's Hide My Email feature reportedly allows users' real email addresses to be exposed. Research indicates that this vulnerability has been successfully exploited, raising serious concerns for user privacy and trust in Apple's claims of protecting user data.
A vulnerability in Apple's 'Hide My Email' tool exposes users' real email addresses, remaining unfixed for over a year. This compromise poses significant privacy risks for users relying on the feature for anonymity.