Observed Signal · Jul 2, 2026 · Security Vulnerability · Source: t3n · Impact: 3/5 · Sentiment: Negative

Apple 'Hide My Email' Bug Reveals Real Addresses

Executive Signal Summary

A security researcher has reported a vulnerability in Apple’s 'Hide My Email' feature (part of iCloud+) that can reveal users’ actual email addresses behind one-time, randomly generated forwarding addresses. According to 404 Media, researcher Tyler Murphy of the data-deletion service Easyoptouts discovered the bug in June 2025 and notified Apple, but the company has not fixed the issue for about a year. 404 Media says it was able to reproduce the disclosure using the exploit supplied by Murphy. Both Murphy and 404 Media withheld technical details to avoid enabling abuse; Apple previously asked the researcher not to publish exploit details. The flaw raises privacy risks, including the ability to link masked addresses to personal data on public people-search sites.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A privacy vulnerability in a major platform's email-masking feature affects user trust and could enable re-identification or abuse linked to email channels, with implications for email-based communication and privacy-sensitive marketing.

SIGNAL RADAR

Track Apple Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Security researcher Tyler Murphy (Easyoptouts) discovered the bug in June 2025 and reported it to Apple.
  • The vulnerability affects Apple’s 'Hide My Email' feature used by iCloud+ subscribers to create one-time, randomly generated forwarding addresses.
  • 404 Media says it reproduced the exploit and was able to reveal the real private email address behind a newly generated one-time address.
  • Apple has been notified but had not fixed the issue for about a year; Murphy and 404 Media declined to publish exploit details at Apple’s request.
  • The flaw could allow attackers to correlate masked addresses with real personal data on publicly accessible people-search services.

Connected Companies & Entities

4 Entities mapped

“The vulnerability affects Apple’s 'Hide My Email' feature used by iCloud+ subscribers to create one-time, randomly generated forwarding addr...”

“404 Media reported that researcher Tyler Murphy discovered the bug in June 2025 and that 404 Media reproduced the exploit using the research...”

“The article includes external content from TargetVideo GmbH that complements the editorial offering on t3n.de....”

Ontology Mapping & Concepts

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: Jul 2, 2026
Original Coverage Title: “Sicherheitslücke: Apples E-Mail-verbergen-Feature soll richtige Adressen verraten”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

PrivacyJul 1, 2026

Bug in Apple’s Hide My Email Exposes Real Addresses

New research reported by 404 Media and summarized by TechCrunch claims a vulnerability in Apple’s Hide My Email feature can reveal users’ real email addresses. Researcher Tyler Murphy, co‑founder of EasyOptOuts, says he informed Apple more than a year ago and that 404 Media tested and verified the issue; in limited volunteer tests Murphy reported 100% of Hide My Email addresses were exploitable. Details of the vulnerability have been withheld from public disclosure to avoid abuse. Murphy warned that people‑search and data broker sites can link exposed emails to additional personal information, increasing privacy risk. TechCrunch contacted Apple for comment. The report follows prior scrutiny of Apple privacy features in 2022 and 2023 for other perceived privacy failures.

Read assessment
IdentityAug 25, 2026

Apple reverses Hide My Email domain change

Apple has reversed a planned change to its Hide My Email feature that would have moved autogenerated addresses to the @private.icloud.com domain. The company confirmed on August 24–25, 2026 that Hide My Email addresses will remain on @icloud.com after user criticism that the proposed domain change would make disposable addresses easier for sites to reject. Daring Fireball reported internal Apple objections to the switch. Earlier reporting from 404 Media documented a Hide My Email bug that leaked users’ real addresses; Apple fixed that bug after being alerted more than a year earlier.

Read assessment
PrivacyMar 30, 2026

Apple Shared Hide My Email Identities With Law Enforcement

TechCrunch reports that Apple provided real identities and account records to federal law enforcement for at least two customers who used its Hide My Email feature. Court documents show the FBI obtained the account holder’s full name, email address and records for 134 anonymized addresses in an investigation related to an allegedly threatening email; Homeland Security Investigations received similar data in a separate identity-fraud probe. Hide My Email (part of iCloud+) generates anonymized forwarding addresses, and Apple says it does not read forwarded messages, but the company retains account metadata and unencrypted content that can be turned over to authorities. The story highlights the limits of email-based privacy protections and broader implications for encrypted messaging and user trust.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.