Apple has officially resolved a significant security vulnerability affecting its iCloud+ “Hide My Email” feature. The flaw, which previously exposed subscribers’ actual email addresses to original senders, was first reported in June 2025 by investigative outlet 404 Media alongside EasyOptOuts co-founder Tyler Murphy.
According to 404 Media, Apple confirmed that a patch was implemented on July 3 to prevent further exposure of protected accounts. Although Apple previously attempted to resolve the issue in March, independent testing by 404 Media verified that the latest update effectively seals the vulnerability.
The leak reportedly occurred when incoming emails were flagged or rejected as spam—a process that frequently took place automatically at the server level. Because these rejected messages often failed to reach user inboxes or spam folders, affected subscribers could not manually verify if their real addresses had been compromised.

Despite the technical resolution, cybersecurity experts caution that residual privacy risks remain. Because external mail hosts typically retain transfer logs, any protected address linked to a “Hide My Email” alias created prior to July 7, 2026, may have been permanently exposed in third-party databases. Consequently, security researchers advise users to generate replacement email aliases to ensure ongoing privacy.

Apple Ad shows the “Hide My Email” feature from iCloud+
In tandem with the technical fix, Apple continues to face legal scrutiny. A class-action lawsuit has been filed against the company in California, alleging that Apple failed to notify iCloud+ subscribers about the vulnerability while continuing to market the “Hide My Email” feature as a secure privacy tool for nearly a year after the flaw was initially disclosed.
Filed in . Read more about Apple, Icloud, Privacy and Security.