Skip to content
feed: live
>_ 0dayNews
apple
● Breaking

Apple fixes Hide My Email leak, year after disclosure

Apple deployed a July 3 fix for a Hide My Email flaw that unmasked real addresses in Mail logs — disclosed to Apple over a year earlier per 404 Media.

Apple fixes Hide My Email leak, year after disclosure
Image: 0dayNews / 0dayNews Editorial · All rights reserved
airgap airgap · Published · 2 min read

Apple pushed the fix on July 3. Confidence: as-reported by The Hacker News citing 404 Media — 2026-07-21.

The bug undermined the point of the feature: real addresses were reaching Mail logs despite a Hide My Email alias in place. Confidence on that impact framing: as-reported.

Timeline

  • ~mid-2025 or earlier. Tyler Murphy, co-founder of EasyOptOuts, disclosed the flaw to Apple. Exact date: not published. The window is 404 Media’s “more than a year” ahead of the July 3 fix.
  • 2026-07-03. Apple deployed a fix. Server-side, per the report. No public Apple advisory ID cited.
  • 2026-07-21. 404 Media published the disclosure; The Hacker News picked it up the same day.

What is confirmed

  • The service leaked real addresses through Mail logs. As-reported.
  • A fix is live as of July 3. As-reported.
  • The gap between disclosure and fix is over a year. As-reported.

What is not confirmed

  • The specific log surface or field carrying the real address. Neither report names an endpoint, header, or log format.
  • Whether the leak was ever exploited in the wild. No claims either way. Treat as unknown, not “safe.”
  • Whether Apple has assigned a CVE or issued its own security advisory. Not stated.
  • How many users were reachable via the flaw during the disclosure-to-fix window.

What to do

  • Nothing to install. Fix is server-side. Post-July 3, the leak is closed per the report.
  • Real addresses exposed pre-fix stay exposed. Aliases don’t retroactively unlink. If a downstream recipient captured a leaked address in that window, they still have it. Rotating a Hide My Email alias to a new one doesn’t recall the old one from any inbox that logged the real address.
  • Assume nothing about scope. No number was published for how many addresses reached logs, or which categories of recipient could see them. If your Hide My Email use is high-stakes (opt-outs, account isolation from a specific counterparty), treat that recipient as if they may have your real address until you have reason otherwise.

Where this sits

The Apple platform beat is normally about kernel bugs and browser sandboxes. This is a service-side privacy failure — the same “Apple’s opaque disclosure timeline” question in a new venue. A year-plus fix window for a privacy feature whose only job is not to leak the thing that just leaked is a data point. What it means: analysis, not confirmed.

Nothing to add on scope, mechanism, or in-the-wild abuse until Apple, 404 Media, or Murphy publishes more.

Sources

Found this useful? Share it.