- Apple says a July 3 patch fully resolved a Hide My Email vulnerability that exposed users’ underlying personal email addresses.
- The Hide My Email flaw reportedly persisted after an earlier attempted fix, raising uncomfortable questions about Apple’s security-response process.
- Researcher Tyler Murphy first alerted Apple to the issue in June 2025, before the problem later drew media attention and legal scrutiny.
- Users should not need to replace existing aliases, but sensitive accounts deserve a quick review after any email privacy failure.
Table of Contents
Hide My Email was supposed to be the private option
Apple’s Hide My Email feature makes a simple promise: give a website an alias, not your actual inbox address. That promise matters more than it might sound. Email addresses are durable identifiers, routinely traded by marketers, abused by scammers and used to stitch together a person’s activity across services. So a flaw that could expose the address behind an alias lands squarely on the uncomfortable gap between privacy branding and privacy engineering.
Apple now says it has fixed that gap. The company told 404 Media it deployed a patch on July 3 and that the update has ‘fully resolved the issue.’ The vulnerability affected iCloud+ and Apple One subscribers using Hide My Email, Apple’s paid-service tool for creating random addresses that forward messages to a user’s real inbox.
For people who actually use it, the appeal is obvious. You can sign up for a retailer, a newsletter or a new app without handing over the same address you use for banking, work or family. The service also lets users receive and reply to mail through the alias, which makes it far more useful than simply creating a disposable inbox and hoping for the best.

But according to reporting from 404 Media, the flaw let outside parties discover the real address attached to an alias. Put bluntly: the curtain was there, but someone had found a way to look behind it. That defeats the primary reason to use the product in the first place.
What Apple says it fixed in the Hide My Email bug
The reported vulnerability was first disclosed to Apple by security researcher Tyler Murphy in June 2025. Murphy said Apple initially indicated that it had addressed the issue, but he later found it was still present. That detail is the part Apple should take seriously, beyond the patch itself. A fix that doesn’t stick can be worse for user confidence than a slow response, because it encourages people to assume a sensitive report has been closed when it hasn’t.
Apple has not publicly laid out the technical mechanics of the flaw, nor has it said how many accounts were affected or whether it saw evidence of abuse. Companies often hold back exploit details while users update or systems are remediated. Fair enough. Yet this is a server-side privacy service, not an iPhone setting where everyone can check for a new software version. Subscribers are being asked to take Apple at its word that the backend change is complete.
Most people can probably accept that for now, but it leaves meaningful questions hanging. How long was the weakness live? Could it be exploited at scale? Was it limited to a particular flow for validating an alias, or did it expose any active Hide My Email address? The distinction matters because aliases tend to accumulate over years, scattered across accounts users may no longer remember.
Apple’s own Hide My Email support documentation says the service generates unique, random addresses that forward mail to a personal inbox. The whole point is to avoid sharing that personal address. Apple’s wording is clear; its implementation, at least until the July patch, apparently fell short.

Why this particular privacy failure cuts deeper
Not every security bug carries the same practical weight. A crash in a niche app is annoying. A flaw involving an email identity service can have a much longer tail. Once a real address is exposed, it can be copied into data brokers’ databases, spam lists and phishing kits. You cannot rotate an email address as casually as you can replace a compromised password.
That’s also why Hide My Email deserves a higher standard than a typical convenience feature. Apple sells iCloud+ partly on privacy and positions itself against ad-tech companies that monetize personal data. I’d argue that makes these failures especially consequential: users aren’t merely buying cloud storage. They’re paying for a layer of distance between themselves and the internet’s relentless appetite for identifiers.
Apple is hardly alone in dealing with alias-email risk. Firefox Relay, SimpleLogin and DuckDuckGo Email Protection all offer versions of the same basic idea: create a buffer between an online service and a permanent address. Each has trade-offs around encryption, reply support, domain control and account recovery. But their shared premise is straightforward. The forwarding system must never become a shortcut to the underlying identity.
Remember when Apple introduced Sign in with Apple and positioned its private relay addresses as an alternative to handing every app your email? Hide My Email extends that philosophy to the wider web. It’s a good idea, frankly. It just becomes difficult to defend when the privacy boundary can reportedly be bypassed.
What iCloud+ subscribers should do now
Apple has not instructed customers to delete and recreate their aliases, and there’s no indication that doing so is necessary after the Hide My Email patch. If the company’s account is accurate, the exposure route is closed at the service level. Still, a little housekeeping is sensible, particularly for people who use aliases on high-value accounts.
- Review the aliases listed in iCloud settings and remove ones tied to services you no longer use.
- Check whether sensitive accounts have strong, unique passwords and two-factor authentication enabled.
- Be more skeptical of convincing phishing messages, especially if an alias was meant to keep your primary address private.
- Use a password manager to track which accounts are tied to which aliases; future cleanup becomes much less painful.
The takeaway isn’t that people should stop using Hide My Email. On balance, an alias remains preferable to giving every storefront and sketchy newsletter your primary address. The risk here was a failure in Apple’s protective layer, not evidence that privacy aliases are inherently pointless.
Still, Apple needs to earn back some confidence with transparency. A concise technical explanation, a clear timeline and confirmation about whether the flaw was exploited would help. Privacy products run on trust in a very literal sense. When that trust breaks, users can’t simply see the damage from their side of the screen. They have to decide whether the company holding the keys is telling the whole story.
My read is that Apple’s July 3 fix may close the immediate hole, but the lasting test is whether it treats this as a one-off embarrassment or a reason to harden the systems behind every privacy promise it makes.

