"We don't know how often hidden email addresses were leaked in email logs." — Tyler Murphy and EasyOptOuts co‑founder Ben Weiner, to 404 Media.
How Hide My Email is supposed to work
Hide My Email is an iCloud+ feature Apple introduced in June 2021 that generates unique, random email addresses that forward messages to a user's personal inbox. The service is designed to let users create disposable addresses to protect their real email and limit spam; forwarding happens automatically so recipients receive messages without revealing the underlying address. Use of the feature requires a paid iCloud+ subscription.
The vulnerability and the public disclosure timeline
Security researchers from EasyOptOuts disclosed the flaw to Apple on June 13, 2025. According to reporting by 404 Media, Apple deployed a fix on July 3, 2026 — more than a year after initial disclosure. Apple reportedly attempted to patch the issue unsuccessfully earlier this year in March and again on June 30, 2026. Specific technical details were withheld while patches were attempted to avoid creating a vector for exploitation; fuller details were published only after the vulnerability had been addressed.
How the leak occurred and who could be exposed
The core problem was straightforward: sending a message to a Hide My Email address that was subsequently rejected as spam could cause the recipient's real email address to appear in email logs. Murphy and Weiner told 404 Media that for many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even when the message was legitimate. Because such messages often never reach a user's inbox, "such emails probably didn't make it to your inbox, so you can't review your spam folder to learn whether you were affected," the researchers said.
While the bug has been resolved, EasyOptOuts warned that a real email address linked to a Hide My Email address created before July 7, 2026, may have been captured in mail transfer logs when non‑malicious emails were bounced. The reporting does not quantify how many addresses were exposed or which hosts were involved beyond the researchers' description of "many major email hosts."
What this means for technologists, end users, and litigants
- Technologists and security teams: the vulnerability highlights how interactions between spam filtering and forwarding services can reveal metadata in mail transfer logs; teams responsible for mail infrastructure and privacy features will likely re‑examine how rejection and bounce handling affect downstream logs.
- End users: customers who relied on Hide My Email to mask their address should know that addresses created before July 7, 2026, could have been logged when messages were bounced as spam, and that absence from the inbox or spam folder does not confirm absence of exposure.
- Litigants and counsel: the timing of disclosure, repeated unsuccessful patch attempts, and the eventual July 3, 2026 fix are now part of the factual record cited in a class action lawsuit alleging Apple misrepresented Hide My Email's privacy guarantees and failed to remedy the defect for more than a year.
The class action and Apple's communications
A class action lawsuit accuses Apple of misleading customers about Hide My Email while charging for the feature. The complaint asserts: "Apple promised Hide My Email as a privacy feature customers paid for, whether directly through iCloud+ or indirectly through Apple's product-wide privacy representations, and failed to deliver it." It further alleges, "Worse, Apple has been fully aware of this problem for over a year and has not fixed it." The complaint also states, "At no point during this period did Apple disable or pause Hide My Email, warn its customers of the flaw, or correct its privacy representations."
The record established by the reporting and the complaint places three facts at the center of the dispute: the existence of a practical path to unmasking forwarded addresses via standard spam rejection handling; a protracted timeline from disclosure to fully deployed fix; and legal claims that consumers were not warned while the vulnerability persisted.
Apple's July 3, 2026 deployment ostensibly stops the specific leak described by the researchers, but the scope of historical exposure — which Hide My Email addresses, how many, and which mail transfer logs captured real addresses — remains undetailed in the reporting. For users who created Hide My Email addresses before July 7, 2026, the possibility that an address was recorded in mail transfer logs when a message was bounced is now explicit; for litigants and security teams, the timing and communications around disclosure and remediation are the immediate focal points.




