Apple's Hide My Email service, part of iCloud+, generates random email aliases that forward to users’ real email addresses to protect their privacy [1, 2, 3]. A security vulnerability discovered in June 2025 allows attackers to uncover the actual email addresses behind these aliases [1, 4, 2, 5, 3].
The flaw was found and reported to Apple on June 11, 2025, by Tyler Murphy, a researcher with EasyOptOuts [1, 4]. A detailed report including reproduction instructions was submitted two days later. Apple acknowledged the issue in July 2025 and said it was reviewing the vulnerabilities [1].
In March 2026, Apple announced that fixes had been applied and asked Murphy to verify. However, Murphy confirmed by mid-March the flaw remained exploitable despite Apple’s claims [1]. He informed Apple again in May that the vulnerabilities were more severe and widespread than initially understood, but Apple did not respond [1].
In late June, Apple again asserted the fixes were in place, but Murphy confirmed the security hole persists [1]. EasyOptOuts tested multiple Hide My Email aliases and reported 100% were vulnerable to revealing the real email address behind the alias [4, 2, 5, 3]. Murphy said, "We don’t know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable" [4]. He added, "Almost anyone can tap into this vulnerability to learn the real email address behind any Hide My Email proxy" [2].
The exact technical details of how the exploit works have not been made public to avoid abuse [4, 2, 5, 3]. Publicly accessible people-search websites can be combined with the flaw to link aliases back to real user information [4, 2]. Apple has asked Murphy to withhold detailed disclosures while it continues investigating [3].
Murphy also expressed frustration at the lack of resolution: "We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer. Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses" [5].
Apple has not announced a new timeline for patching the vulnerability. Users should remain cautious about relying on Hide My Email aliases for their privacy until a confirmed fix is released.