Apple's Hide My Email Flaw Persisted, Exposing User Addresses After Multiple Patch Claims

Apple publicly claimed fixes on March 3 and June 30, 2026, but independent researchers found exploitable behavior after both claims; Apple later said a patch was deployed around July 3, 2026 and that the vulnerability was fully resolved, though testers still observed issues two weeks later.
AppleInsider independently reproduced the vulnerability on July 17, 2026, roughly two weeks after Apple's claimed fix, suggesting the patch did not fully close the gap.
The technical trigger involved sending a message to a Hide My Email alias that was rejected as spam, causing the real address to appear in mail server logs (a leakage mechanism that can occur even if the message isn’t delivered to an inbox).
404 Media began reporting the flaw in early July after Tyler Murphy’s initial alerts in June 2025, with Murphy and EasyOptOuts providing test data and Apple engaging in a prolonged vetting process before public disclosure.
Apple took more than a year to fully patch a flaw in its Hide My Email feature that could expose users' real email addresses, according to MacRumors and 404 Media. The fix was officially deployed around July 3, 2026 — but independent tests showed the vulnerability still worked two weeks later.
Security researcher Tyler Murphy, founder of EasyOptOuts, first reported the flaw to Apple in mid-2025. Apple claimed fixes on March 3 and June 30, 2026, but researchers found both claims fell short. The drawn-out timeline has raised sharp questions about how Apple handles privacy bugs.
Hide My Email lets users send and receive messages through a random alias, keeping their real address hidden. The flaw broke that protection in a specific scenario. When a sender's message was rejected as spam, the real address behind the alias appeared in mail server logs, according to MacRumors. No inbox delivery was needed — the leak happened at the server level.
The attack did not require advanced skills. WebProNews reported that an attacker only needed to target one address at a time. Still, for someone who knew what to look for, it was a reliable way to strip away the privacy Hide My Email is designed to provide.
Apple told researchers it had fixed the issue on March 3, 2026. Murphy's tests showed it was still exploitable. Apple claimed a second fix on June 30, 2026. Researchers found that did not work either. Apple then said a third patch went live on July 3, 2026, and that the issue was fully resolved, according to MacRumors.
From Murphy's first report in mid-2025 to Apple's third claimed fix in July 2026, the flaw remained open for over a year. WebProNews noted that Apple engaged in a prolonged vetting process before the issue was made public, with 404 Media beginning its coverage in early July 2026 after Murphy's alerts the previous June.
Apple said the July 3 patch fully closed the gap. But AppleInsider independently reproduced the vulnerability on July 17, 2026 — 14 days after Apple's claimed repair date. That test raised serious doubts about whether the third fix was any more complete than the first two.
AppleInsider noted the flaw affected users with pre-existing Hide My Email addresses. Even if Apple's patch eventually holds, experts warn that mail transfer logs already captured during the vulnerable period could still expose real addresses in bounce scenarios — meaning the risk does not disappear the moment a patch goes live.
Apple has not said how many users were affected or whether any real addresses were exposed in the wild. The company has stated the issue is now fully resolved. Users who rely on Hide My Email aliases for privacy — especially those created before July 2026 — may want to generate new aliases as a precaution, given that old addresses could appear in retained server logs.
The episode highlights a broader tension in how Apple manages security disclosures. The company's slow, multi-attempt response to a privacy flaw in a flagship privacy feature drew criticism from researchers. MacRumors reported that Murphy spent over a year pushing Apple toward a working fix, with public disclosure only coming after multiple failed patches.
Publishers
13
Articles
8
Reach
21