Particle.news

Apple Says It Has Patched Hide My Email Vulnerability

Apple's patch aims to stop a bug that let bounced spam reveal real addresses, leaving older aliases possibly linked in third‑party mail logs.

Overview

  • Researchers first reported the Hide My Email flaw to Apple in June 2025 after finding that a message rejected as spam could cause mail‑transfer logs to record a user’s real address behind an alias.
  • 404 Media publicly disclosed the vulnerability in early July 2026 and Apple told the outlet it deployed a patch on July 3, which the company says resolved the issue.
  • Independent tests reported by AppleInsider reproduced the exploit on July 17, raising questions about whether the July 3 deployment completed across all servers and providers.
  • Experts say the flaw did not expose passwords or inbox contents but did break Hide My Email’s anonymity because bounced or rejected messages could surface real addresses in third‑party logs.
  • A proposed class action in California seeks refunds and an injunction over Apple’s privacy claims and users are advised to treat aliases created before July 7, 2026 as potentially exposed while Apple clarifies its rollout and log‑retention risks.