Tech

Apple patches iCloud+ Hide My Email flaw amid class action allegations

The US tech giant deployed a fix on 3 July 2026 after reports revealed the service allowed senders to uncover users' primary email addresses via spam rejection logs.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Engadget · original
Apple has reportedly fixed its Hide My Email vulnerability
Privacy feature vulnerability exposed real addresses; lawsuit seeks fee recovery

Apple has released a software patch for its iCloud+ Hide My Email service, addressing a vulnerability that permitted senders to reveal a user's real email address when messages were rejected as spam. The fix was deployed on 3 July 2026, following disclosures by researcher Tyler Murphy and reporting by 404 Media. Murphy, co-founder of EasyOptOuts, cautioned that the risk persists for emails sent prior to 7 July 2026 due to potential retention in third-party mail transfer logs. Concurrently, a proposed class action lawsuit has been filed alleging deceptive conduct and seeking the recovery of subscription fees.

The vulnerability allowed senders to uncover a user's primary email address by sending a message to a hidden address that was subsequently rejected as spam. Apple originally introduced the Hide My Email feature in 2021 to generate dummy email addresses for privacy. According to 404 Media, the company claims the July 3 patch completely resolved the issue, ending the ability to easily view the addresses the service is designed to obscure.

Tyler Murphy initially disclosed the vulnerability to Apple in June 2025. Over several months, the company investigated the issue and claimed to have fixed it. However, Murphy reported that he was still able to find hidden email addresses, prompting Apple to review the matter again. When the company appeared unable to fully resolve the problem, Murphy contacted 404 Media with his findings in early July 2026. Reports indicate Apple had been aware of the issue for at least a year prior to the final patch.

Despite the technical fix, Murphy warned that the risk to users has not been entirely eliminated. He noted that non-malicious emails could bounce, revealing hidden email addresses, and that mail transfer logs are often retained by third parties. Consequently, any hidden email address linked to a Hide My Email address created before 7 July 2026 may have been exposed and could still exist in third-party logs.

The incident poses a significant challenge to Apple's public image, which is heavily based on its commitment to privacy. The notion that the company was selling a privacy-focused feature that failed to protect user data has drawn legal scrutiny. PCMag reports that a proposed class action lawsuit has been filed against Apple, seeking an injunction against the company's alleged deceptive conduct and the full recovery of subscription fees paid by customers for the feature. Engadget has contacted Apple for comment but has not yet received a response.

Continue reading

More from Tech

Read next: France passes legislation banning social media for under-15s and mobile phones in schools
Read next: LG and Prime Video introduce Creator Original mode for 2026 OLED evo TVs
Read next: Best Buy Black Friday in July Sale Targets Late Summer Electronics Buyers