Particle.news

Hide My Email Vulnerability Lets Aliases Reveal Users' Real Addresses

Independent testing verifies the exploit remains usable with no public confirmation of a fix from Apple.

Overview

  • A privacy researcher first reported the flaw to Apple in June 2025 and 404 Media independently verified the exploit this week, showing an alias can be traced back to the underlying iCloud account email.
  • In limited volunteer tests the researcher said every Hide My Email alias tested was exploitable, indicating the flaw works reliably across generated addresses.
  • Technical details of the exploit are being withheld by reporters and researchers to prevent abuse because the vulnerability remains live and usable in production.
  • Apple has told the researcher it was investigating and at times said a change had addressed the issue, but the company has not publicly confirmed a completed patch or given a timetable for remediation.
  • Apple’s planned move to consolidate aliases on the private.icloud.com domain will make relay addresses easier for services to detect or block, and exposed real emails can be linked to names and locations via public people‑search and data‑broker sites, increasing real-world safety risks for users who relied on Hide My Email.