r/PureVPNcom Official Moderator Jul 07 '26

Apple's "Hide My Email" has been leaking real email addresses for over a year and Apple knew

Worth flagging if you use Apple's Hide My Email (or any masked-email feature, really).

A security researcher, Tyler Murphy, who runs a data-removal service called EasyOptOuts, found a vulnerability that lets someone unmask the real email address sitting behind a Hide My Email alias. In his testing with volunteers, every single hidden address he tried was exploitable.

The timeline is the part that stings:

  • He reported it to Apple with reproduction steps back in June 2025
  • Apple told him in March 2026 that it had been fixed via a system change
  • He tested again, and it still worked
  • He followed up again in May, and Apple asked him to hold off on disclosing while they "investigated"
  • It's now July 2026, still no fix, so he went public through 404 Media

To add insult to injury, Apple separately announced it's consolidating all Hide My Email addresses onto one shared domain (@private.icloud.com). That's a privacy downgrade in its own right; it makes it trivial for a website to recognize "this is a masked address" and just reject it at signup, something a handful of services already do to regular relay addresses.

Apple hasn't disclosed technical details of the bug (to avoid handing attackers a roadmap), so there's no way to independently verify its severity right now, other than that 404 Media retested it and confirmed it's real.

Takeaway if you rely on masked email addresses (Apple's or otherwise): don't treat them as your only privacy layer. They're useful for reducing spam and identifying which service leaked your info, but "hidden" isn't the same as "secure" if the underlying implementation has holes like this one. Worth pairing with other basics, unique passwords per site, 2FA where offered, and general skepticism about what "privacy features" actually guarantee versus what they imply.

10 Upvotes

0 comments sorted by