Monday, August 3, 2026

Apps & Consumer

Apple’s Hide My Email feature reportedly exposes user addresses

A researcher claims a bug in Apple’s Hide My Email feature allows real email addresses to be unmasked, a vulnerability reportedly left unaddressed for over a year.

Apple’s Hide My Email feature reportedly exposes user addresses

A bug in Apple’s Hide My Email feature—a tool that uses disposable addresses to provide online anonymity—appears to allow users’ real email addresses to be unmasked, according to reports from 404 Media. The media outlet reported that it has tested and verified that the vulnerability exists. While the full scope of the issue remains unclear, in limited tests with volunteers, 100% of the Hide My Email addresses were found to be exploitable. To prevent malicious actors from taking advantage of the flaw, specific details of the vulnerability have not been publicly disclosed.

Tyler Murphy, the researcher who found the bug, claims he warned Apple about the security flaw over a year ago. Murphy, who is also the co-founder of EasyOptOuts—a company that offers a paid data-removal service to take personal information off of data broker sites—expressed concern that the vulnerability remains unaddressed. Murphy stated that while the full scope of the issue is unknown, 100% of the Hide My Email addresses were exploitable in limited tests with volunteers. He added that all attempts to exploit the bug have been successful, and noted that it is unclear why Apple has yet to remedy the problem. He warned that “publicly accessible people-search sites make it easy to link an email address to other personal details, so people relying on Hide My Email for safety may be at risk.”

This incident adds to a history of privacy concerns for Apple, which has been accused of this sort of thing before. For instance, the company was sued in 2022 after reports surfaced that iPhone apps continued to send analytics data to Apple even when the iPhone Analytics privacy setting was turned on. In 2023, researchers found another one of Apple’s privacy features to be effectively “useless.” The research claimed that a tool that was supposed to anonymize mobile users’ Wi-Fi connections by providing randomized MAC addresses (an easily trackable identifier) was simply exposing the user’s real MAC address.

Why it matters

Apple has built its brand on user privacy, but this bug—and the company’s failure to address it after a year—undermines that promise and leaves users vulnerable to data brokers.