The Simple Exploit of Apple’s “Hide My Email” Feature
Apple’s “Hide My Email” service promises users enhanced privacy by allowing them to create random email addresses that forward to their actual accounts. However, a recent vulnerability illustrated that this promise of anonymity was more fragile than previously thought.
The Vulnerability Uncovered
Reports revealed that anyone could easily discover the real email addresses hidden by the “Hide My Email” feature. This unfortunate oversight occurred when spam-like messages were sent to an alias address. Apple’s servers would reject these emails, which resulted in a “bounce” message that inadvertently disclosed the actual email address intended to be hidden. The individuals behind these hidden addresses remained blissfully unaware, as Apple had known about this security flaw for over a year.
Timeline of Events
The issue first came to light on June 11, 2025, when security researchers Ben and Tyler Murphy notified Apple about the potential breach. They provided additional details on June 13 and 20, and further insights on July 9. It wasn’t until July 14, 2025, that Apple publicly acknowledged the problem, and the company claimed to have resolved it by March 3, 2026—comparable to the length of a human pregnancy.
Repeated Failures of Apple
Unfortunately, Apple’s claims to have fixed the issue turned out to be false. The Murphy brothers pointed out further vulnerabilities, including a more severe flaw they reported on May 22, 2026. Despite Apple’s reassurances of a fix on June 30, it was later determined that the issue was not adequately resolved. This led the Murphy brothers to escalate the issue by reaching out to media outlets like 404 Media.
Impact of Media Exposure
The media scrutiny forced Apple to take the matter more seriously, and as of early July, it seems that the exploit was mitigated. Tyler Murphy confirmed that the spam trick no longer worked, but he warned that residual risks might still exist. Non-malicious emails could still “bounce” and inadvertently reveal real email addresses. Additionally, since email logs are often retained for extended periods, any aliases created before July 7 might have been compromised.
Legal Consequences
On July 15, a California resident filed a lawsuit against Apple, seeking damages and a restraining order. The case, known as Anthony Alvarez v. Apple, is currently pending in the U.S. District Court for Northern California. This legal action underscores the seriousness of the privacy breach, as it covers all U.S. users of the “Hide My Email” feature.
Conclusion
Apple’s “Hide My Email” feature was designed to enhance user privacy, yet it exhibited glaring vulnerabilities that could expose users’ real email addresses. The initial oversight, compounded by Apple’s delayed response and repeated failures to correct the issue, has raised serious concerns about user privacy and trust in Apple’s services. As users, it’s essential to remain vigilant and understand the potential risks associated with any privacy features, regardless of the provider’s reputation.

