403/69 Thursday, July 23, 2026

Apple has fixed a security vulnerability in its Hide My Email service on iCloud+, a feature designed to generate random email addresses to conceal users’ real email addresses and help prevent spam. The vulnerability could allow users’ real email addresses to be exposed through email delivery logs, undermining the privacy protection purpose of the service. The issue was reported by a security researcher in mid-2025 and was fully resolved at the server level in early July 2026.
The root cause of the vulnerability occurred when an email was sent to a Hide My Email random address and the message was rejected by the system as spam. The bounce process caused the recipient’s real email address to be automatically recorded in the mail transfer logs of major email providers. Users could not detect the issue themselves because the messages never reached their inbox or spam folder. Although Apple previously attempted to patch the issue in March and June 2026, due to the duration of the problem, real email addresses linked to Hide My Email addresses created before July 7, 2026, may have been recorded in historical mail logs. The issue has also led to legal action against Apple over transparency and user privacy protection concerns.
Because this fix was implemented on the server side, users do not need to manually update their devices. However, users who created and used Hide My Email addresses before the fix and are concerned about potential exposure can reduce risk by deactivating existing random email addresses and creating new ones for important services. Users should also remain cautious of phishing emails or impersonation attempts that may use information from historical mail logs and should continue to monitor security guidance from the service provider.
Source: https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html
