Apple patched a vulnerability in Hide My Email that could reveal users’ real email addresses when messages sent to an alias were rejected as spam, exposing the underlying address in email logs. Researcher Tyler Murphy of EasyOptOut reported the issue to Apple in June 2025, but reports say the company did not fully remediate it until July 3, 2026, after public coverage highlighted that the flaw remained exploitable despite an earlier claim that it had been fixed.
Limited testing by the researcher indicated that all tested Hide My Email aliases were vulnerable, and users who created addresses before July 7, 2026 may still face exposure through retained third-party mail logs generated before the patch. The incident has triggered a proposed class action lawsuit accusing Apple of false advertising and consumer protection violations, with plaintiffs seeking reimbursement of subscription costs and an injunction related to the service.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A lawsuit was filed against Apple over the Hide My Email vulnerability, seeking class action status, recovery of subscription costs, and injunctive relief. The complaint alleges false advertising and consumer protection violations tied to the privacy feature.
Researchers warned that Hide My Email addresses created before 2026-07-07 may still have been exposed through retained third-party mail logs. The warning indicated that historical logs could continue to reveal real email addresses even after the patch.
Apple told Tyler Murphy in March 2026 that the Hide My Email vulnerability had been fixed. However, the flaw reportedly remained exploitable after that response.
EasyOptOuts co-founder Tyler Murphy reported a Hide My Email flaw to Apple in June 2025. The issue could expose a user's real email address when messages sent to an alias were rejected as spam.
Apple deployed a patch for the Hide My Email vulnerability on 2026-07-03, more than a year after the initial report. The fix came after 404 Media covered the issue, according to the reports.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcethecyberexpress.com
Open sourcethehackernews.com
Open source404media.co
Open sourcemacrumors.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.