Apple patched a significant security flaw in its iCloud+ Hide My Email feature on July 3, 2026, more than 13 months after the vulnerability was first reported. The fix only came after a tech news outlet made the bug public, raising serious questions about how one of Apple's most-marketed privacy tools handled a known exposure gap for over a year.
What the Flaw Actually Did
Hide My Email generates unique, random email addresses that forward messages to a user's personal inbox, with the purpose of safeguarding user privacy and reducing unwanted spam. The feature requires a paid iCloud+ subscription and was introduced by Apple in June 2021.
The flaw undermined that promise in a specific but serious way. Murphy discovered that sending a specially crafted email that was rejected as spam could cause the recipient's real email address to appear in mail transfer logs. If someone sent a message to a hidden address and it bounced as spam, the user's actual email address could get exposed in the sender's mail logs, and the user would have no way of knowing it happened, since a bounced message never lands in their inbox.
The vulnerability did not expose passwords, Apple Accounts, or inbox contents. Instead, it undermined Hide My Email's core privacy promise by potentially allowing an alias to be linked back to a user's permanent email address.
According to Murphy and his EasyOptOuts co-founder Ben Weiner, as reported by iClarified, "For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message."
A Year of Inaction Before a Public Disclosure Forced the Fix
404 Media reported that a fix was deployed by Apple on July 3, 2026, after more than a year since the vulnerability was disclosed to the company by Tyler Murphy, co-founder of EasyOptOuts.
The timeline tells a frustrating story. Murphy reported the flaw in June 2025, but despite Apple claiming it was resolved in March 2026, independent tests confirmed it remained exploitable at least until July 3, 2026. In the following months, Apple said it was again looking into the problem, but Murphy was unconvinced Apple would actually address it, so he contacted 404 Media to make it public.
After another unsuccessful fix attempt in late June, he contacted 404 Media, which published the story on July 1. Apple deployed the patch two days later.
The vulnerability turned out to be fairly low-tech, failing to hide the main email address in spam email logs that were bounced back to the sender after being rejected.
The Fix Is In, But Older Aliases May Still Be Exposed
Apple says it fixed the vulnerability on or around July 3, but AppleInsider successfully reproduced the flaw two weeks after the company's claimed repair date. By July 21, both Apple and Murphy confirmed the bug had been fully resolved.
Even so, the researcher's warning to users is pointed. As Engadget reports, Murphy stated: "Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs."
Users should treat real addresses attached to older aliases as potentially disclosed, and understand that deleting an alias will not erase information already retained in another provider's logs.
Legal Fallout and What It Means for Marketers
The disclosure prompted legal action. Per the class action complaint, researchers first reported the flaw in June 2025, and while Apple acknowledged the report, the company allegedly "took no action for nearly a year" while researchers finally went public in July 2026 after a year of inaction and no security update from Apple. The plaintiff states he is one of the millions of customers who paid Apple for iCloud+ and relied on Apple's representations that Hide My Email would keep his personal email address hidden.
For email marketers and growth teams, this story carries a practical implication beyond the privacy debate. Subscribers who use Hide My Email addresses ending in @privaterelay.appleid.com or @icloud.com are doing so because they want to guard their real identity from the services they sign up with. Seeing an unusual increase in iCloud addresses on your list may signal that people don't trust your brand, and as one email deliverability expert noted, "This has always been a reflection of the level of trust the recipient has with your business or org." 
When subscribers use alias addresses, it affects suppression management, re-engagement campaigns, and list hygiene. If a relay address bounces (as this flaw demonstrated was possible), email service providers may flag or suppress that address, removing a real person from your list without any indication of what happened. Growth teams should audit bounce logs for relay-domain patterns and treat hard bounces from privaterelay.appleid.com addresses with extra care until the full scope of historical exposure is better understood.
Apple's delayed response also reinforces a broader lesson: privacy promises in your own marketing need to hold up under scrutiny. Subscribers are increasingly aware of email privacy tools, and brands that handle contact data transparently, with clear opt-in practices and respectful data use, are the ones that earn real addresses in the first place.



