• Sources: 404 Media, HN discussion
  • Summary: 404 Media reported that Apple patched a flaw in its iCloud+ Hide My Email masking service on 2026-07-03 after the outlet's coverage. Sending a Hide My Email user a message that the mail server rejected as spam could reveal the user's real address in server logs. Researcher Tyler Murphy of EasyOptOuts first reported the issue to Apple in June 2025 and found it remained exploitable across roughly a year before the fix. A class-action lawsuit over the vulnerability has been filed.
  • Why it matters: Hide My Email is a privacy primitive many people rely on, and a year-long unfixed leak of the address it exists to protect undercuts that guarantee.

send feedback on this story