Overview
- Security researcher Tyler Murphy of EasyOptOuts privately reported a method to link Apple-generated aliases to real addresses in June 2025, according to multiple outlets.
- 404 Media and EasyOptOuts reproduced the issue in recent tests and Murphy says the exploit worked on all of the aliases his team tried.
- Apple has told researchers it applied fixes during system changes and on June 30, 2026 said the problem was resolved, but testers report the vulnerability remains exploitable.
- Murphy and 404 Media withheld full technical details to avoid enabling attackers while they provided those details privately to Apple, and Apple has not published a verifiable remediation or detailed public comment.
- The bug threatens the core purpose of iCloud+ aliasing by allowing re-identification of users, which could enable linking to public records and further erode trust in paid privacy features.