Ethical Hacking News
Apple’s Hide My Email service, designed to provide users with an additional layer of privacy when signing up for online services, has been exposed as vulnerable. The system fails to protect user email addresses, leaving millions potentially at risk. This article delves into the details of the discovery and the implications for Apple and its users.
Apple's Hide My Email service was found to be vulnerable, exposing users' real email addresses.A total of 100% of Hide My Email addresses were exploitable, according to security researcher Tyler Murphy.The vulnerability remained unaddressed despite initial claims that it had been fixed by Apple.The incident highlights systemic failures in security measures at major tech companies and the need for greater transparency and accountability.
Apple’s Hide My Email service, designed to provide users with an additional layer of privacy when signing up for online services, has been exposed as a vulnerable system that fails to protect user email addresses. In June 2025, security researcher Tyler Murphy discovered a vulnerability in the system that made it possible for people's real email addresses to be uncovered when using Apple's privacy service.
According to reports from 404 Media, Murphy conducted tests with volunteers and found that 100% of Hide My Email addresses were exploitable. This means that anyone using the service could potentially have their real email address linked back to their new, randomly generated email address. The vulnerability was first reported by Murphy in June 2025, but Apple claimed it had been "addressed" by March this year.
However, when Murphy continued testing the issue, he found that the problem remained exploitable. Apple told Murphy a couple of months ago that it was still investigating the issue and did not respond to requests for comment from the publication.
This discovery highlights the systemic failures of security measures in place at major tech companies. Apple's Hide My Email service is designed to provide users with an additional layer of privacy, but its vulnerability shows that even the most well-intentioned security measures can fail when not properly implemented or tested.
The situation is particularly concerning given the increasing reliance on online services and the importance of protecting user data. The discovery of this vulnerability serves as a reminder that no system is completely secure, and companies must prioritize the implementation of robust security measures to protect their users.
Furthermore, this incident highlights the need for greater transparency and accountability in the tech industry. Apple should be held accountable for its failure to address this issue promptly and effectively. The company's response to Murphy's initial report and subsequent investigation raises questions about its commitment to user privacy and security.
In light of this discovery, Apple must take immediate action to rectify the situation and ensure that its Hide My Email service is secure. This includes conducting thorough testing and implementing patches to address the vulnerability. The company should also provide clear guidance to users on how to protect themselves from similar threats in the future.
The incident also raises questions about the broader implications of this vulnerability. How many users have been affected by this issue? What other potential vulnerabilities exist within Apple's services? These are important questions that need to be answered, and Apple must take proactive steps to address them.
In conclusion, the discovery of a vulnerability in Apple's Hide My Email service highlights the systemic failures of security measures in place at major tech companies. The situation serves as a reminder of the importance of prioritizing user privacy and security and the need for greater transparency and accountability in the tech industry.
Related Information:
https://www.ethicalhackingnews.com/articles/A-Systemic-Failure-of-Security-Apples-Hide-My-Email-Service-Exposed-as-Vulnerable-ehn.shtml
https://www.wired.com/story/security-roundup-apples-hide-my-email-service-fails-to-hide-your-email/
Published: Sat Jul 4 05:49:43 2026 by llama3.2 3B Q4_K_M