Apple Fixes Hide My Email Flaw That Exposed Users’ Real Email Addresses
ID: f1934d84-61ea-51fc-8463-ef6ffdfb3c17
STIX ID: report--f1934d84-61ea-51fc-8463-ef6ffdfb3c17
Feed Name: Cyber Press
Apple patched a long-standing vulnerability in iCloud+ Hide My Email that allowed bounced emails to reveal the underlying real email addresses of users. Researcher Tyler Murphy reported the issue in June 2025 and Apple applied a patch on July 3, 2026, though independent tests initially found the unmasking technique still worked; experts warn that historical mail logs may retain exposed addresses and advise treating aliases created before July 7, 2026 as potentially compromised. A proposed class-action lawsuit alleges Apple misrepresented the feature while charging for iCloud+.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
