A vulnerability in Apple's Hide My Email feature can expose users' real email addresses, a problem discovered and reported by Tyler Murphy. Testing conducted on June 30, 2026, confirmed the vulnerability remained active despite Apple's statements about addressing the issue.

Murphy originally reported the vulnerability to Apple in June 2025. Apple responded in July 2025, indicating it was investigating the matter. In March 2026, the company stated it had resolved the issue through a recent system change; however, Murphy's subsequent checks found the problem persisted. In May 2026, Apple issued a statement indicating it was still investigating the vulnerability. Later that month, the company announced plans for a future security update in the coming weeks to address the issue. Murphy provided replication instructions and details of the ongoing problem to 404 Media on June 30, 2026.

Murphy stated that "Apple Hide My Email is leaking email addresses that are supposed to be hidden." He added, "We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable."

404 Media is not publicly disclosing the specific details of the vulnerability because it remains exploitable. "We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer," Murphy said. Hide My Email is a component of Apple's paid iCloud+ service, designed to allow users to generate anonymous email addresses that typically consist of two random words and a number ending in the @icloud.com domain.

Why It Matters

This situation involves a reported security vulnerability in a privacy feature offered by a major technology company that remained unaddressed for over a year after its initial report. The Hide My Email feature is designed to protect user privacy by masking personal email addresses; its potential compromise could undermine user expectations of privacy and expose individuals relying on the service to unintended data exposure. The sustained presence of the vulnerability, despite Apple's previous claims of resolution and ongoing investigations, indicates a potential delay in addressing user privacy concerns.