Full Breakdown
Apple’s Hide My Email Feature Exposes Real Addresses Amid Ongoing Investigation
7/2/2026, 12:15:34 PM
The Vulnerability Unveiled
Apple’s iCloud Plus “Hide My Email” service, marketed as a disposable-address tool for privacy, contains a flaw that lets anyone retrieve the user’s actual email address. Independent testing by Easy Opt Out co-founder Tyler Murphy demonstrated that every generated alias could be linked to its real counterpart using publicly available people-search sites.
Background & Prior Privacy Concerns
Hide My Email creates “@icloud.com” aliases that expire after a set period, allowing users to avoid sharing personal addresses. Apple plans to shift the alias domain to “private.icloud.com” this summer, a change that could affect how websites filter such addresses. The bug follows earlier privacy setbacks for Apple, including a 2022 lawsuit over iPhone analytics data and a 2023 discovery that its MAC-address randomization feature exposed real identifiers.
Key Figures & Groups
Timeline of Disclosure and Response
- June 2025: Murphy alerts Apple to the vulnerability.
- March 2026: Apple announces it has “addressed” the problem.
- May 2026: Apple states the issue remains under investigation and asks Murphy not to publicize details, citing customer-risk concerns.
- May 2026 (later): Murphy confirms the bug persists after Apple’s March claim.
- Summer 2026: Apple signals upcoming updates, including the domain change to “private.icloud.com.”
Data & Statistics
- 100 % of Hide My Email aliases tested by Murphy’s team were traceable to the real email address.
- Tests employed volunteers and standard identity-search tools available to any internet user.
Official Statements & Responses
Apple’s spokesperson indicated that the company had taken steps to remediate the issue in March 2026 but continued to investigate its scope in May, requesting discretion from the researcher to protect users. Murphy reiterated that he warned Apple over a year ago, that all exploitation attempts succeeded, and that the flaw endangers users who rely on the service for anonymity.
Criticism & Opposition
Murphy warned that “publicly accessible people-search sites make it easy to link an email address to other personal details, so people relying on Hide My Email for safety may be at risk.” Critics argue that the bug undermines Apple’s long-standing privacy branding and raises doubts about the company’s ability to safeguard its own privacy tools.
Conflicting Reports & Gaps
Apple’s March statement claimed the problem was resolved, yet Murphy’s May findings indicate the vulnerability remained. No technical details of the flaw have been disclosed, and independent verification beyond Murphy’s tests is absent, leaving the full scope of exposure unclear.
Verbatim Quotes
- “We don’t know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable,” — Tyler Murphy, Easy Opt Out
- “publicly accessible people-search sites make it easy to link an email address to other personal details, so people relying on Hide My Email for safety may be at risk.” — Tyler Murphy, Easy Opt Out
- “All of the attempts to exploit the bug have been successful, Murphy added.” — Tyler Murphy, Easy Opt Out
- “To avoid placing our customers at risk, we would appreciate you not disclosing this information until our investigation is complete.” — Apple spokesperson
What’s Next
Apple intends to roll out updates to Hide My Email this summer, including the shift to the “private.icloud.com” domain. Observers will watch for a definitive fix and for any further disclosures about the bug’s technical nature.
