READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Apple's Hide My Email Has Leaked Real Addresses for at Least a Year, Researcher Says

Apple's Hide My Email Has Leaked Real Addresses for at Least a Year, Researcher Says
A security flaw in Apple's Hide My Email privacy feature has allowed real email addresses to be traced back through their anonymized aliases for at least a year, according to researcher Tyler Murphy. Murphy reported the issue last summer, Apple claimed it was addressed by March 2026, but Murphy's continued testing showed it remained exploitable. Apple has not publicly commented.

Apple launched Hide My Email in 2021 as part of its iCloud+ subscription. The pitch was straightforward: generate a random @icloud.com alias, hand that to websites instead of your real address, and keep your actual inbox private. For users paying for privacy, the promise seemed solid. The service had a critical flaw.

Security researcher Tyler Murphy discovered in June 2025 that the service had a vulnerability allowing anyone to link a Hide My Email alias back to the real address behind it. According to reporting by 404 Media, Murphy tested the flaw with volunteers and found 100% of Hide My Email addresses were exploitable in those tests.

"Apple Hide My Email is leaking email addresses that are supposed to be hidden," Murphy told 404 Media.

Murphy reported the flaw to Apple last summer. Apple told him the issue had been "addressed" by March 2026. Murphy kept testing. It wasn't fixed. Apple then told Murphy, a couple of months before this report, that it was still investigating the issue. That puts the known, reported vulnerability window at at least a year with no public fix and no public disclosure from Apple.

Apple did not respond to 404 Media's requests for comment.

The technical specifics of how the exploit works have been withheld by both Murphy and 404 Media, a responsible-disclosure decision given that Apple has not patched it.

Hide My Email exists precisely to prevent data brokers, advertisers, and bad actors from linking online accounts back to a real identity. If the alias can be resolved to the underlying address, the privacy guarantee collapses entirely. Users who signed up for services using Hide My Email aliases, believing their real addresses were protected, may have had that protection undermined for at least a year without knowing it.

The flaw doesn't appear to require sophisticated access. The fact that it worked in 100% of Murphy's volunteer tests suggests this isn't an edge-case issue affecting a narrow slice of configurations.

Responsible disclosure norms exist for exactly this reason. Apple has not patched the flaw publicly, but it also hasn't denied the issue. The company told Murphy it was "still investigating," which could reflect genuine technical complexity rather than indifference. Large-scale changes to authentication or email-forwarding infrastructure can carry downstream risks that slow remediation. Some would argue that publishing even the existence of an unpatched vulnerability raises the risk of exploitation before users can be protected. That's a legitimate engineering concern. It doesn't, however, change the basic fact: Apple sold a privacy feature, the feature has a known flaw, Murphy reported it last summer, and users have no patch and no official warning.

The Hide My Email story was part of a wider set of security disclosures in recent days. A member of the European Parliament's PEGA Committee, the body specifically created to investigate Pegasus spyware abuses, was reportedly targeted with Pegasus himself, according to research findings covered by Wired. Separately, a researcher found that Anthropic's Claude Opus 4.7 could be used to access the Front Gate ticketing platform and generate tickets for major U.S. festivals including Lollapalooza and Bonnaroo. And a Wired investigation revealed that Meta contractors posed as minors to test how AI chatbots including Gemini and ChatGPT responded to prompts involving suicide, sex, and drugs.

Apple has not said when a fix will be deployed or whether it plans to notify affected iCloud+ users. Until a patch ships and Apple confirms it, every Hide My Email alias created since at least June 2025 should be treated as potentially traceable to the real address behind it.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredSecurity Roundup: Apple’s Hide My Email Service Fails to Hide Your Email