Reports Confirm Privacy Flaw in Apple’s Hide My Email Remains Unaddressed

Hide My Email is widely used on iOS, with about 55% of iOS Mail users having it enabled in 2023, meaning a large user base could be affected by any flaw.
Independent testing claimed a 100% success rate in leaking the real email from generated Hide My Email aliases, suggesting the flaw could fully defeat the feature's anonymity promise.
Apple said the issue was addressed in a March 2026 system change, but researchers including Tyler Murphy contend the vulnerability remains unrepaired in practice.
Details of the vulnerability have been withheld to prevent exploitation, with public disclosure limited as Apple and researchers handle the issue.
Public verification of the flaw has occurred, with 404 Media reporting that it verified the issue and demonstrated replication instructions to Apple more than a year after the initial report.
Apple's Hide My Email feature — a privacy tool used by millions of iCloud+ subscribers — has a serious unfixed flaw that can reveal users' real email addresses. 404 Media independently verified the vulnerability on June 29, 2026, confirming that a hidden alias can still be traced back to its owner's actual inbox. Apple was first told about the problem in June 2025, over a year ago.
Tyler Murphy, co-founder of the privacy firm EasyOptOuts, discovered the flaw and says his tests showed a 100% success rate in cracking aliases. He told 404 Media: "Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses." Apple told Murphy on June 24, 2026, that it expects a fix "in the coming weeks" — but the hole remains open today.
Murphy first reported the flaw to Apple in June 2025, with step-by-step instructions to reproduce it. Apple acknowledged the report in July 2025 and said it was investigating. Then, in March 2026, Apple told Murphy the issue had been "addressed in a recent system change," according to Mashable. Murphy tested it again. The flaw was still there.
Between April and May 2026, Murphy gave Apple more evidence that the bug persisted. Apple asked him to stay quiet while it ran "additional checks," MacWorld reported. On June 29, 2026, 404 Media ran its own test with fresh accounts and confirmed the vulnerability was still fully exploitable — more than 12 months after Murphy's original report.
Hide My Email creates random aliases — like "x7k2m@icloud.com" — that forward to a user's real inbox. The idea is that no one can link the alias back to the real address. But Murphy's tests cracked that link in about five minutes, according to Daring Fireball. That means an attacker could start with a fake address and end up at someone's true identity.
The stakes are high for vulnerable people. Email addresses are the "primary key" data brokers use to build profiles on individuals, Softonic noted. A leaked alias can be combined with free people-search sites to find a user's home address, phone number, and more. Privacy experts warn this is especially dangerous for domestic abuse survivors, activists, and anyone trying to avoid being doxxed.
On top of the unfixed flaw, Apple is planning another change that critics say undermines the feature further. The American Bazaar reported in June 2026 that Apple intends to move Hide My Email aliases from the standard "@icloud.com" domain to a new "@private.icloud.com" subdomain by late summer 2026. Today, aliases look identical to regular iCloud accounts. After the change, they won't.
That matters because websites could simply block all "@private.icloud.com" addresses at the door, according to Bitdefender. Users who get blocked would be forced to hand over their real email addresses to sign up. The change that was meant to modernize the system could end up making the privacy feature useless for the very services people most want to hide their identity from.
The scale of the problem is significant. About 55% of iOS Mail users had Hide My Email turned on as of 2023, Softonic reported. Apple's iCloud+ is tied to a broader ecosystem serving over 1.2 billion iOS app subscribers, according to MacDailyNews. Apple's total revenue hit $416 billion in 2025. Critics say a company that size should have fixed a single privacy bug in far less than a year.
Researchers and analysts are calling the situation a failure of accountability. Mashable noted that Apple's March 2026 claim of a fix that didn't work points to either poor internal testing or a fundamental misunderstanding of the exploit. Murphy and 404 Media chose to go public on July 1, 2026, but withheld the technical details to avoid helping attackers while the flaw stays open.
Publishers
13
Articles
11
Reach
24