Apple Fixes Security Flaw Exposing Users' Hidden Email Addresses
Apple has addressed a serious security vulnerability in its Hide My Email service, part of the iCloud+ subscription, which exposed users' real email addresses. The flaw was discovered by security researcher Tyler Murphy in June 2025 and reported to Apple. It involved spam emails sent to anonymous addresses being blocked or rejected, but the real email addresses were inadvertently recorded in mail server logs, allowing third parties to link anonymous emails to users' actual addresses without their knowledge.
Apple released a patch on July 3, 2026, after extended discussions with the researcher. However, Murphy warns that email addresses created before July 7, 2026, may still be at risk due to the retention of mail server logs over time. Users are advised to update their Apple devices immediately to apply the fix and consider recreating any anonymous email addresses generated before the patch date to prevent ongoing exposure.
This incident highlights the importance of vigilance in protecting online privacy. While Apple has resolved the issue on its end, users must take proactive steps to safeguard their real email addresses and continue benefiting from the Hide My Email service without risking spam or privacy breaches.