Skip to content
← All news
3 min read

Apple Says It Fixed Hide My Email. AppleInsider Broke It Again Two Weeks Later.

A patch Apple called complete failed a retest two weeks after it shipped, and Apple has not explained why.

Apple told reporters its Hide My Email fix was complete. Two weeks later, the leak still worked.

Apple told 404 Media in early July that it had fully resolved a bug in Hide My Email that let a sender unmask a user's real address behind an alias. On July 17, AppleInsider ran the same exploit again. It still worked, two weeks after the claimed fix.

How the exploit unmasks an alias

Hide My Email lets an iCloud+ user hand out a throwaway address that forwards to a real inbox without exposing it. The whole feature's value is that a sender only ever sees the alias. The bug sits in what happens when a message to that alias bounces. Security researchers Tyler Murphy and Ben Weiner of EasyOptOuts found that when a message sent to an alias trips spam filters at many major mail hosts, the resulting bounce or transfer notice can leak the real address into the receiving mail server's own logs. That's a system Apple does not control and cannot patch directly, which is exactly why the bug was so hard to close cleanly: the leak happens on someone else's infrastructure, triggered by ordinary spam handling rather than anything unusual an attacker has to build.

Thirteen months from report to patch

Murphy and Weiner reported the bug to Apple in June 2025. Nothing about it became public until 404 Media wrote about it in early July 2026, more than a year later. Apple then told the outlet it had shipped a fix on July 3 that fully resolved the issue. There was no security advisory, no CVE, and no public explanation of what changed in the fix. The only account of it came from a statement to a reporter, which is a thin paper trail for a bug that touches every Hide My Email user's real inbox address.

A retest that didn't hold

AppleInsider independently reproduced the exploit on July 17, two weeks after Apple's claimed patch date, using the same bounce mechanism Murphy and Weiner originally described. Apple has not commented on the failed retest as of this writing. Aliases created before July 7 may stay exposed even once the underlying bug is fully closed, since a real address already logged at a third-party mail host cannot be recalled after the fact. A class action lawsuit has since been filed alleging Apple's marketing of Hide My Email as private was misleading given how long the company knew about the gap.

Why a build studio cares

We build systems that promise users privacy through aliasing and masked identifiers, and the failure mode here is the one worth remembering: a promise that holds in the happy path and breaks on a rejection or a retry nobody tested. Most of these bugs live at the boundary between your system and someone else's, exactly where Hide My Email's leak lives, in a third party's bounce log rather than Apple's own servers. A patch that cannot survive an independent retest two weeks later was not actually the fix, and a one-line statement to a reporter is not a substitute for a public advisory that says what broke, what changed, and who is still exposed.

Next step: read 404 Media's report on the fix and AppleInsider's retest. If you're building alias or identity infrastructure and want a second pair of eyes on the edge cases, write to hello@gattyworks.com.

privacyapplesecurityAppleHideMyEmailiCloudPlusPrivacyBreachDataPrivacyEmailSecurityCyberSecurityAppleInsiderInfoSecTechNews

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.