Apple says it has fixed a vulnerability in its Hide My Email feature which let essentially anyone figure out a user’s real email address which was supposed to be protected by the feature. Apple only fixed the vulnerability
after 404 Media wrote about it
at the start of July, despite Apple knowing about the issue for more than a year.
The news also follows the
filing of a class action lawsuit
against Apple over the vulnerability.
On Wednesday Apple told 404 Media it deployed a patch for the issue on July 3, which the company says has fully resolved the issue. 
Hide My Email is part of Apple’s paid iCloud+ product. It lets customers quickly create a new, anonymous email address they can then use to sign up to websites, services, or email people with. The generated email addresses typically contain two random words followed by a number and the @
icloud.com
domain. I use it heavily so hackers may have a harder time cross-referencing my activity and accounts across data breaches, for example. 
💡
Do you know about any other privacy issues like this? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.
Tyler Murphy,
co-founder of EasyOptOuts
, discovered he was able to find the real email address of Hide My Email users. At the time, Murphy said, “We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.” That included mine, which we tested.
Murphy first reported the issue to Apple in June 2025. Over the subsequent months, Apple said it was looking into the issue and said it had fixed it; Murphy found it was still exploitable; and Apple again said it was looking into it. Murphy, thinking Apple may not fix the issue at all, then contacted 404 Media, around a year after Apple learned of the vulnerability.

When 404 Media first covered the issue several weeks ago, we did not include any details on ho

… [more]