TL;DR
A security researcher revealed that Apple’s Hide My Email service has a vulnerability allowing real email addresses to be exposed. The flaw has persisted for over a year, raising privacy concerns. Apple has yet to confirm a fix.
Apple’s Hide My Email service has been found to leak users’ real email addresses, according to security researcher Tyler Murphy and a recent report from 404 Media. The flaw allows malicious actors or unintended parties to uncover the actual email linked to a generated, anonymous address, undermining the privacy protections the feature was designed to provide. This vulnerability has reportedly existed for over a year and remains unpatched, raising significant privacy concerns for users relying on the service.
In a report published by 404 Media, security researcher Tyler Murphy disclosed that a flaw in Apple’s Hide My Email feature enables the exposure of users’ real email addresses. Murphy, who discovered the flaw in June 2025, stated that in limited tests involving volunteers, 100% of the generated email addresses could be linked back to the user’s actual email. Despite reporting the issue to Apple last summer and receiving assurances it was addressed by March 2025, subsequent testing revealed the flaw persisted. Apple has not publicly responded to requests for comment, and the company’s ongoing investigation into the issue suggests it remains unresolved.
The vulnerability specifically affects addresses created under the @icloud.com domain, which are intended to be anonymous and forward messages to the user’s primary email. The exact technical details of how the leak occurs have not been disclosed, but the research indicates a significant breach of privacy, potentially exposing sensitive user information to malicious actors or third parties.
Implications for User Privacy and Trust
This flaw undermines the core promise of Apple’s privacy tools, which are widely used by users seeking to limit data sharing with third parties. The exposure of real email addresses could lead to targeted phishing, spam, or identity theft, especially if malicious actors exploit the vulnerability. The revelation also raises questions about Apple’s security review processes and its commitment to user privacy, which is a key selling point for its ecosystem. For users, this exposes a potential risk of data leaks and a loss of trust in Apple’s privacy features.
Apple Hide My Email privacy protection
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Background on Apple’s Privacy Features and Past Security Incidents
Apple introduced the Hide My Email feature in 2021 as part of its broader push to enhance user privacy, enabling users to generate unique, random email addresses that forward messages to their primary inbox. The feature was designed to prevent companies from collecting users’ actual email addresses, reducing spam and protecting identities. Since its launch, the service has been considered a privacy safeguard for millions of users.
However, security vulnerabilities in Apple’s ecosystem have occasionally surfaced, including past issues with iCloud data leaks and other privacy-related bugs. The current disclosure adds to a history of security challenges faced by Apple, highlighting the ongoing importance of rigorous testing and transparency in privacy protections.
“Apple Hide My Email is leaking email addresses that are supposed to be hidden.”
— Tyler Murphy, security researcher
email anonymizer tools
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Technical Details and Fix Status Still Unclear
It is not yet confirmed how exactly the vulnerability operates or whether it affects all users universally. Apple has not publicly detailed the technical nature of the flaw or provided a timeline for a complete fix. It remains unclear if the issue has been fully patched or if additional security measures are forthcoming.
secure email forwarding services
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Apple’s Response and Ongoing Security Investigations
Apple has acknowledged the investigation into the vulnerability but has not issued a public fix or timeline for resolution. Security researchers and users will be monitoring updates from Apple in the coming weeks. Further disclosures may emerge as Apple completes its review and implements security patches.
privacy-focused email apps
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
How does the vulnerability in Hide My Email work?
The exact technical details have not been publicly disclosed, but it involves a flaw that allows the linking of generated email addresses to real ones, potentially through server-side or domain configuration issues.
Has Apple confirmed the vulnerability?
Apple has not publicly confirmed or acknowledged the specific flaw but is reportedly investigating the claims.
Who is affected by this vulnerability?
Any user relying on Apple’s Hide My Email feature since its launch in 2021 could be affected, especially if their generated address was compromised or linked back to their real email.
What should users do now?
Users should stay informed about official updates from Apple and consider additional privacy measures if concerned, until the vulnerability is confirmed fixed.
Will Apple fix this vulnerability?
Apple has stated it is investigating the issue; a fix is anticipated but has not been officially announced yet.
Source: WIRED