TL;DR
Open a free Amazon Business account
Business pricing, bulk buying and tax-exempt orders.
Create a free accountAs an affiliate, we earn on qualifying purchases.
A security flaw in Apple’s ‘Hide My Email’ feature allows attackers to discover users’ real email addresses. Apple has known about the issue for more than a year but has yet to fix it. The vulnerability poses privacy risks for users relying on the service.
Security researchers have confirmed a vulnerability in Apple’s ‘Hide My Email’ feature that can expose users’ actual email addresses, despite the service’s purpose of maintaining anonymity. Apple has been aware of the issue for over a year but has not yet released a fix, raising concerns about user privacy and security.
The vulnerability was discovered by an independent researcher who tested the ‘Hide My Email’ feature, which is part of Apple’s iCloud+ subscription. The researcher was able to retrieve real email addresses linked to hidden addresses by exploiting a flaw in the system. This flaw has been verified through multiple tests, with 100% of the tested addresses being exploitable in controlled conditions.
The researcher first reported the issue to Apple in June 2025. Despite ongoing communications, Apple has not implemented a fix, although the company claimed to have addressed the problem in a system update earlier this year. However, subsequent testing revealed the flaw persisted, and Apple continued to investigate as of May 2026. The researcher expressed concern that the vulnerability remains active, and the company has not responded to multiple requests for comment.
Experts warn that this flaw could allow malicious actors to link anonymous email addresses to real identities, especially since publicly accessible sites can connect email addresses with other personal data. This undermines the privacy protections that ‘Hide My Email’ aims to provide and could expose users to targeted attacks or identity theft.
Potential Privacy Risks for Users Reliant on ‘Hide My Email’
This vulnerability undermines a key privacy feature used by many Apple users to mask their personal email addresses. If exploited, it could lead to the exposure of sensitive personal information, increasing the risk of targeted scams, phishing, or identity theft. Given the widespread adoption of the feature among privacy-conscious users, the flaw poses a significant security concern that remains unaddressed despite being known for over a year.

ZAGG InvisibleShield Glass Privacy Screen Protector For Apple iPhone
- Full-Screen Privacy: Two-way filtered privacy protection
- Impact Protection: Chemically strengthened for durability
- Responsive Touch: Ultra-smooth, beveled edges for sensitivity
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Background and Timeline of the Vulnerability Discovery
‘Hide My Email’ is a privacy tool introduced by Apple as part of iCloud+ that generates random, disposable email addresses linked to a user’s Apple ID. This allows users to sign up for services or communicate without revealing their actual email address. The flaw was discovered by an anonymous researcher who tested the feature and confirmed the ability to retrieve real email addresses linked to hidden addresses.
The researcher reported the issue to Apple in June 2025. Apple acknowledged the report and indicated it was investigating, claiming to have addressed the problem in a system update earlier this year. However, subsequent tests confirmed the flaw persisted, and Apple continued to investigate into May 2026. The researcher expressed frustration at the delay in fixing the vulnerability, which remains active as of the latest tests.
“We don’t know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.”
— an anonymous researcher

ANNKE 3K PoE Security Camera with Red & Blue Strobe Flash Light Alarm, IP67
- Compatibility: Works best with ANNKE NVRs
- Resolution: 3K Super HD with wide view
- Detection: Human and vehicle detection with high accuracy
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Extent and Impact of the Vulnerability Remain Unclear
While tests confirm the vulnerability’s existence and exploitability in controlled environments, the full scope—such as how many users are affected and whether the flaw can be exploited remotely at scale—remains unknown. Apple has not provided detailed technical disclosures or a timeline for a complete fix, and the investigation is ongoing.
disposable email address generator
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Expected Security Update and Continued Investigation
Apple has announced plans to address the issue in a future security update, expected within the coming weeks. Meanwhile, researchers and users await a definitive fix. It is also anticipated that Apple may change how generated email addresses are formatted, which could impact the effectiveness of the feature and its security posture.

Digital Freedom: The 7-Day AI System to Organize Your Phone, Email, Photos, Files, and Passwords—and Take Back Your Time, Focus, and Peace of Mind
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
How does the vulnerability allow discovery of real email addresses?
The flaw exploits a weakness in the way Apple links or displays hidden email addresses, enabling an attacker to retrieve the actual email linked to a ‘Hide My Email’ address through certain technical manipulations.
Has Apple acknowledged the vulnerability?
Apple has acknowledged the issue and indicated it was investigating, but has not confirmed a complete fix or provided detailed technical disclosures. The company has not responded to multiple requests for comment as of now.
Who is most at risk from this vulnerability?
Users relying heavily on ‘Hide My Email’ for privacy and security are at risk if their real email addresses are exposed. Malicious actors could link these addresses to personal identities or use them for targeted attacks.
Will future updates fix the problem?
Apple has stated that a fix is planned for a future security update, expected within weeks. The effectiveness of this fix remains to be seen, and further technical details are awaited.
Could changing the email address format reduce the vulnerability?
According to reports, Apple plans to modify the generated email addresses from ‘@icloud.com’ to ‘@private.icloud.com’, which could make it more difficult for attackers to link addresses but may also impact the feature’s overall effectiveness.
Source: 404 Media
Baby shower & registry season Picks
baby registry must-haves
As an affiliate, we earn on qualifying purchases.