Apple is facing a proposed class action lawsuit alleging that its Hide My Email feature exposed users’ real email addresses to websites and apps despite being marketed as a privacy protection. The complaint says the flaw allowed aliases generated through iCloud+ to be linked back to a user’s actual address, potentially defeating the purpose of the service and raising claims under California false advertising and consumer protection laws.
According to the filings, a security researcher reported the issue to Apple in June 2025, Apple acknowledged it the following month, later said in March that it had addressed the problem, and then indicated in May that a patch would be released within weeks, but the lawsuit alleges the vulnerability remained unresolved. The suit seeks compensation for iCloud+ subscribers and other users who paid for privacy protections that allegedly did not work as advertised, while reports say there are no known cases of active exploitation and technical reproduction details have not been publicly disclosed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
According to the complaint, Apple later told the researcher in May that a patch would be released within weeks. The lawsuit alleges the vulnerability still had not been fully resolved afterward.
The lawsuit alleges Apple stated in March that it had addressed the Hide My Email flaw. However, the complaint claims the issue remained unresolved despite that representation.
The Fox Business report says Apple acknowledged the reported Hide My Email issue in July 2025 after the researcher disclosed it. This marked Apple's recognition of the alleged privacy flaw.
Apple was hit with a proposed class action lawsuit alleging its Hide My Email privacy feature exposed users' real email addresses and violated consumer protection laws. The suit seeks compensation for affected iCloud+ subscribers and other users who paid for privacy protections that allegedly did not work as advertised.
According to the lawsuit, a security researcher disclosed a vulnerability in Apple's Hide My Email feature to Apple in June 2025. The reported flaw allegedly allowed aliases to be linked back to users' real email addresses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcefoxbusiness.com
Open sourcemacrumors.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.