Home / Blog / Apple Fixes Hide My Email Vulnerability After 404 Media…
Tech News

Apple Fixes Hide My Email Vulnerability After 404 Media Coverage

By Dillip Chowdary • Jul 21, 2026 • Source: Hacker News Front Page

Apple has patched a vulnerability in Hide My Email that allowed essentially anyone to recover a user’s real email address from an address that was supposed to stay private. Apple told 404 Media it deployed the fix on July 3 and says the issue is fully resolved. The company only shipped the patch after 404 Media published its reporting at the start of July, even though Apple had known about the flaw for more than a year. A class action lawsuit over the same vulnerability has also been filed against Apple.

Hide My Email is a paid iCloud+ feature that generates disposable, anonymous addresses for sign-ups, services, and outbound mail. Those addresses typically look like two random words plus a number at the @icloud.com domain. The product’s job is straightforward: break the one-to-one link between a person’s permanent inbox and every site that collects an email, so a leaked alias cannot be mapped back to the real account. The bug undercut that isolation: if a relay address could be tied back to the underlying identity, the privacy boundary the feature advertises did not hold.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

For engineers and product builders, this is a concrete failure mode of privacy-as-a-service. Users adopt relay inboxes specifically to reduce cross-site correlation after breaches and scrapes. When that mapping leaks, the risk is not abstract—it is account linking, targeted phishing, and identity stitching that the user thought they had paid to avoid. Anyone shipping similar alias, proxy, or “hide my identity” flows has to treat reverse-resolution paths as security boundaries, not secondary concerns, and assume that researchers and attackers will probe them hard.

The timing also lands in a familiar industry pattern: a known defect sits for more than a year, public reporting forces a fix, and legal exposure follows. 404 Media’s coverage, the July 3 deployment, and the class action sit in sequence rather than in isolation. Paid privacy features are a competitive differentiator for iCloud+; a long-lived gap between discovery and remediation weakens the claim that subscription privacy tooling is reliably maintained under pressure, not only marketed well.

Practical takeaway: treat Hide My Email as partially restored after the July 3 patch, not as never-broken history—anyone who relied on those aliases during the unpatched window should assume the real address may have been recoverable. Watch next for how Apple documents residual risk, how the class action proceeds, and whether other consumer privacy relays get similar reverse-lookup scrutiny now that this case is public.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →