- Apple has fixed a vulnerability in its Hide My Email feature that exposed users' real email addresses, following coverage by 404 Media.
- The issue was known to Apple for over a year before it was addressed, with the patch deployed on July 3.
- Tyler Murphy discovered the vulnerability and reported it to Apple in June 2025, stating that 100% of tested Hide My Email addresses were exploitable.
- Despite the fix, experts warn that the risk to users may not be fully eliminated, as non-malicious emails could still reveal hidden addresses.
- The class action lawsuit against Apple seeks full recovery of subscription costs for the Hide My Email feature and an injunction against the company for its 'deceptive conduct'.
- The Hide My Email feature allows users to generate unique email addresses that forward to their personal inbox, protecting their real email when signing up for services.
Apple has fixed a vulnerability in its Hide My Email feature that allowed unauthorized access to users' real email addresses, a flaw known for over a year. The issue was first reported by Tyler Murphy in June 2025, who discovered that 100% of Hide My Email addresses were exploitable in limited tests.12345689
Despite being aware of the problem, Apple only deployed a patch on July 3, after coverage by 404 Media. Murphy noted that the vulnerability was triggered when emails were automatically rejected as spam, potentially leaking hidden email addresses to senders.
“We don't know how often hidden email addresses were leaked in email logs,” Murphy stated, emphasizing that legitimate emails could also bounce, revealing users' hidden addresses. He and EasyOptOut co-founder Ben Weiner expressed concerns that any hidden email address linked to a Hide My Email account created before July 7, 2026, may still be exposed in third-party logs.
In response to the breach, a class action lawsuit has been filed against Apple, seeking full recovery of subscription costs and an injunction for its 'deceptive conduct.' Apple maintains that the issue has been fully resolved, but the risk to users remains a concern.
The vulnerability highlights the ongoing challenges in digital privacy, even with features designed to protect user information.
“Apple knew about the vulnerability for over a year before fixing it, and a class action lawsuit now seeks recovery of subscription costs for the feature. The exploit allowed senders to discover real email addresses when messages were automatically rejected as spam, according to researchers.”
