Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Awareness of Vulnerability: Apple's Fix for Hide My Email Exposes Real Addresses in Mail Logs


Awareness of Vulnerability: Apple's Fix for Hide My Email Exposes Real Addresses in Mail Logs

In a recent turn of events, Apple has been left with no choice but to address a security flaw that had been plaguing its popular email service, Hide My Email. The issue allowed users' real email addresses to be unmasked from the service's unique and random email addresses, raising significant concerns about user privacy.

  • Apple's Hide My Email service has been found to have a security flaw that exposed users' real email addresses.
  • The bug allowed targeted messages sent to registered email addresses to reveal the real email address in the service's logs.
  • A fix was deployed by Apple, but concerns remain about potential data exposure for accounts created before July 7, 2026.
  • The incident highlights the importance of robust cybersecurity measures and prioritizing user safety.



  • In a recent turn of events, Apple has been left with no choice but to address a security flaw that had been plaguing its popular email service, Hide My Email. The issue, which was first reported over a year ago, allowed users' real email addresses to be unmasked from the service's unique and random email addresses. This revelation comes as a significant blow to Apple, which had previously touted its Hide My Email feature as a means of safeguarding user privacy.

    The bug, which was exposed by Tyler Murphy, co-founder of EasyOptOuts, worked in such a way that simply sending a targeted message to a user's registered email address would trigger the service's spam filters. This, in turn, would reveal the real email address associated with the Hide My Email account in the email logs. It is worth noting that the bug had been identified by Apple over a year ago, yet it took them nearly 10 months to deploy a fix for the issue.

    According to Murphy and EasyOptOuts co-founder Ben Weiner, the crux of the problem lay in the fact that many major email hosts have a leak triggered simply by an email being automatically rejected as spam. This means that even legitimate messages could potentially be flagged as spam, resulting in the real email address being exposed in the email logs.

    The issue has significant implications for users who rely on Hide My Email to safeguard their privacy. As Apple is currently facing a class-action lawsuit alleging that it misled customers about the privacy of its Hide My Email feature while charging for it, this latest development only adds fuel to the fire.

    In an effort to rectify the situation, Apple has deployed a fix for the bug in question. The update aims to prevent users' real email addresses from being exposed in the service's logs. However, concerns have been raised that even though the bug has been resolved, it is still possible that real email addresses linked to Hide My Email accounts created before July 7, 2026, may have been captured in mail transfer logs.

    As Apple continues to navigate this complex landscape of data exposure and privacy concerns, one thing is certain: users can expect heightened scrutiny from security experts and lawmakers alike. The incident serves as a stark reminder of the importance of robust cybersecurity measures and the need for companies like Apple to prioritize user safety above all else.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Awareness-of-Vulnerability-Apples-Fix-for-Hide-My-Email-Exposes-Real-Addresses-in-Mail-Logs-ehn.shtml

  • https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html


  • Published: Tue Jul 21 15:22:41 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us