Apple fixed a security flaw in its iCloud+ Hide My Email service that exposed subscribers’ real email addresses in mail server logs.
Apple has quietly deployed a software fix to resolve a significant privacy vulnerability in its flagship iCloud+ “Hide My Email” service that allowed third parties to discover subscribers’ real email addresses. Unveiled by security researchers and verified by media outlets on Tuesday, July 21, 2026, the year-long flaw undermined the primary privacy guarantee of Apple’s paid alias feature. Hide My Email is designed to let iCloud+ users generate unique, random @icloud.com addresses for website sign-ups and communications, forwarding incoming messages to their personal inboxes while keeping their actual email address hidden. However, an operational bug in how mail servers handled bounced messages enabled senders to bypass this privacy barrier and extract underlying personal email addresses directly from mail transfer logs.
The core technical mechanics that made this vulnerability so severe involved mail-handling protocols for rejected messages. When an attacker or automated sender transmitted a specially crafted message to a target’s Hide My Email alias, such as an email structured to be flagged and rejected as spam- the mail system’s automated bounce handling generated mail logs that inadvertently recorded the user’s permanent, real email address. Security researcher Tyler Murphy, co-founder of data removal service EasyOptOuts, discovered the flaw and demonstrated that sending a message designed to bounce back to the sender caused mail servers to leak the hidden destination address. In controlled volunteer testing, Murphy reported that 100 percent of tested Hide My Email addresses were susceptible to exposure.
Examining the exposure highlights risks spanning global email provider infrastructure and third-party mail logs. Because Hide My Email forwards messages across various international mail servers, the leak occurred within mail transfer logs retained by major email hosting platforms. Because non-malicious messages or routine spam filter rejections could trigger the bounce mechanism automatically, affected subscribers were often completely unaware that their real email address had been recorded in third-party server logs, rendering standard inbox review ineffective for detecting exposure.
Tracing the timeline of this flaw reveals a prolonged disclosure period that has sparked widespread scrutiny. Murphy first reported the vulnerability to Apple on June 13, 2025. Over the subsequent 12 months, Apple repeatedly assured researchers the issue was under investigation, claiming on at least two occasions, in March and late June 2026, that fixes had been implemented, only for testing to confirm the exploit remained active. After Murphy went public with investigative outlet 404 Media in early July 2026, Apple finalized a server-side patch that it confirmed went live on July 3, 2026. However, security experts advise that any Hide My Email alias created before July 7, 2026, should be treated as potentially exposed in historical server logs.
See Also: Modern SOCs Are Moving Beyond EDR to Multi-Layered Detection Systems
The strategy behind the public fallout centers on user trust and growing legal liabilities for Cupertino. Subscribers pay monthly fees for iCloud+ specifically to shield their personal identity from data brokers, spammers, and marketing trackers. The failure to remediate a core privacy defect for over a year has triggered a proposed class-action lawsuit in California, alleging that Apple engaged in deceptive trade practices by continuing to market and profit from a privacy feature it knew was flawed.

