CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Apple Patches Hide My Email Flaw That Leaked Real Addresses in Mail Logs

July 21, 2026

Apple has fixed a critical privacy flaw in its Hide My Email service that could expose users’ real email addresses through mail transfer logs. The bug, disclosed by Tyler Murphy and Ben Weiner of EasyOptOuts, allowed a sender to trigger the leak simply by having their message automatically rejected as spam. Apple deployed the fix on July 3, 2026, after more than a year since the initial report on June 13, 2025. The company attempted patches in March and June 2026 before finally resolving the issue. Hide My Email, a feature requiring an iCloud+ subscription, generates random forwarding addresses to protect user privacy. The flaw undermines that guarantee, and Apple now faces a class action lawsuit alleging it misled customers about the feature’s privacy protections while continuing to charge for it. Users who created Hide My Email addresses before July 7, 2026, may have had their real addresses captured in logs when non-malicious emails bounced. Apple has not disabled the service or warned customers during the year-long period.

Companies: Apple, EasyOptOuts

Products: Hide My Email, iCloud+