Apple Fixes Hide My Email Privacy Vulnerability After Year-Long Delay
Key Takeaways
- ▸Apple delayed fixing a critical Hide My Email vulnerability for over a year despite being notified in June 2025
- ▸The flaw allowed attackers to discover real email addresses by sending messages that would be automatically rejected as spam
- ▸A class action lawsuit has been filed against Apple over the vulnerability and its slow response to the security issue
Summary
Apple has patched a critical vulnerability in its Hide My Email service that allowed attackers to discover users' real email addresses despite the feature's privacy protections. The flaw, reported to Apple in June 2025, required sending target users messages that would be rejected as spam, potentially revealing their actual email addresses to senders and being retained in email logs. Despite knowing about the issue for over a year, Apple only deployed the fix on July 3, 2026, following disclosure by security researchers and reporting by 404 Media.
The vulnerability affected all Hide My Email users, with a 100% exploitation rate in security tests conducted by researchers at EasyOptOuts. The delay in patching the issue has prompted a class action lawsuit against Apple seeking full refunds of iCloud+ subscription costs and damages for allegedly deceptive conduct. Security experts have cautioned that any Hide My Email addresses created before July 7, 2026, should be considered potentially compromised, as they may still exist in third-party email logs.
- Security experts recommend assuming all Hide My Email addresses created before the July 2026 patch date may have been exposed to third parties



