Key takeaways
- Murphy discovered that Hide My Email aliases can be traced back to users’ real email addresses through a flaw in Apple ’s iCloud mail server backend.
- Hide My Email is a core feature of iCloud+, Apple’s paid storage plan that begins at a monthly subscription fee.
- In June 2026, Apple announced plans to shift Hide My Email addresses from the @icloud.com domain to @private.icloud.com, a change communicated to developers via official notes.
- Recent court records reveal that Apple has provided the FBI with real iCloud email addresses hidden behind Hide My Email aliases when served with legal process.
Apple’s “Hide My Email” privacy feature, designed to shield users from advertisers and data brokers by masking their real email addresses, contains a critical vulnerability that allows attackers to uncover hidden email addresses with near-perfect reliability. Security researcher Tyler Murphy, co-founder of EasyOptOuts, first reported the flaw to Apple in June 2025, yet as of July 2026—over a year later—the vulnerability remains unresolved and actively exploitable. Independent verification by technology journalists confirms the exploit works against live accounts, exposing millions of iCloud+ subscribers to privacy breaches.
A Year-Old Vulnerability Still Unpatched
Murphy discovered that Hide My Email aliases can be traced back to users’ real email addresses through a flaw in Apple’s iCloud mail server backend. In volunteer testing, Murphy reliably exploited every single hidden address he attempted, demonstrating that the vulnerability is not theoretical but practical and reproducible. The researcher told 404 Media that “Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses,” a statement made after verifying the exploit against test accounts and confirming independent confirmation of the vulnerability as recently as Monday in July 2026.
Apple’s response timeline reveals a pattern of delayed remediation. In July 2025, one month after Murphy’s initial report, Apple stated it was investigating the issue. By March 2026, Apple claimed the issue had been “addressed in a recent system change”—a statement Murphy found to be false. The company issued further updates in April and May 2026, promising a fix “in the coming weeks,” but those assurances proved empty. As of publication, the vulnerability persists unfixed, leaving iCloud+ subscribers exposed for over 12 months.
The Stakes for Apple’s Premium Privacy Service
Hide My Email is a core feature of iCloud+, Apple’s paid storage plan that begins at a monthly subscription fee. The feature is unavailable to users on Apple’s standard free 5 GB iCloud plan, meaning only paying customers can access this privacy tool. The vulnerability directly undermines the value proposition of iCloud+, which positions itself as a privacy-first service that shields users from commercial tracking and data exploitation.
The technical mechanism of the flaw lies in how the iCloud mail server handles replies to messages sent through Hide My Email aliases. When users reply to emails sent to their masked addresses, the reply-to header includes their real email address, defeating the core purpose of anonymity at the moment users need it most. This backend implementation flaw affects virtually all users of the feature and cannot be worked around by individual subscribers without abandoning the service entirely.
Apple’s Domain Migration May Compound the Problem
In June 2026, Apple announced plans to shift Hide My Email addresses from the @icloud.com domain to @private.icloud.com, a change communicated to developers via official notes. While this migration may theoretically address some attack vectors, security experts worry it could make the feature less effective in practical use. Many email providers and online services use domain-based filtering rules; the unfamiliar @private.icloud.com domain could trigger rejections from services that have not updated their systems, effectively breaking Hide My Email for legitimate users.
Murphy stated publicly that “we don’t feel comfortable waiting any longer,” signaling frustration with Apple’s extended timeline. Apple had requested that Murphy refrain from disclosing the vulnerability until the company completed its investigation—a request honored through May 2026. However, the extended silence and repeated false assurances about fixes have pushed the security researcher to go public with the details, prioritizing user awareness over Apple’s preferred timeline.
Government Access and the Limits of Apple’s Privacy Claims
Recent court records reveal that Apple has provided the FBI with real iCloud email addresses hidden behind Hide My Email aliases when served with legal process. This disclosure demonstrates a critical limitation in Apple’s privacy model: while Hide My Email protects users against commercial tracking and data brokers, it offers no protection against federal government subpoenas or law enforcement requests. Apple controls the encryption keys for iCloud email accounts, meaning the company can and does comply with government demands for user identification.
This distinction between commercial privacy and government access has significant implications for how users should evaluate the feature’s actual protective scope. Hide My Email functions as a commercial privacy tool, not a security mechanism against state actors or law enforcement. Users relying on the feature for protection against government surveillance have been operating under a false sense of security, as Apple’s own actions with the FBI demonstrate.
Next Steps and User Guidance
Apple has not issued specific public guidance on the vulnerability or timeline for remediation as of July 2026, though the company is expected to address the bug in a forthcoming iOS or macOS security update. Users are advised to monitor Apple’s official security updates closely and consider supplementary privacy measures such as dedicated alias services from third-party providers or VPN services that offer email masking features. The extended vulnerability window suggests that relying solely on Hide My Email for privacy protection may be insufficient.
This incident underscores the tension between Apple’s marketing of privacy features and the technical reality of their implementation. A feature that fails to protect user anonymity for over a year after discovery represents a significant gap between promise and performance, particularly for the millions of iCloud+ subscribers who have paid specifically for enhanced privacy protections. The vulnerability’s persistence and Apple’s delayed response have eroded trust in the company’s privacy commitments and raised questions about the robustness of other privacy-focused features within the Apple ecosystem.