Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
As others have said, this sort of thing really breaks Apple’s privacy ‘brand promise’.

Not fixing it after a year is not a good look.

And given that Apple practices ‘privacy through obscurity’:

Is private relay actually doing what Apple says?

Ditto will the Apple Intelligence Secure Enclave?
I mean… it’s not being exploited… even though it, apparently, hasn’t been fixed. FOR A YEAR. That’s either saying something about the skills of the malicious actors out there OR it’s saying something about how ACTUALLY difficult it is to set up the conditions where it can be done.

If the exploit requires something like a user sharing an unencrypted network via an unlocked phone in close proximity to the attacker and leave their phone unlocked for as long as the attacker needs (because they asked them to), then I can understand how Apple wouldn’t put a lot of effort into fixing it to the level that the author thinks it needs to be fixed.

The author is getting the attention they craved, though. 🙂
 
  • Like
Reactions: bluecoast
"Privacy. That's Apple."

"Privacy is a fundamental human right. It’s also one of our core values. Which is why we design our products and services to protect it. That’s the kind of innovation we believe in."


Source: https://www.apple.com/privacy/
And you take that to mean “App vendors don’t collect more information than people are aware of”? It doesn’t really say anything about what App vendors do OR about how clueless many people are when choosing to allow the app to track them via a nicely worded screen. 🙂
 
"May be possible"

That's doing a lot of heavy lifting here.
A herculean level of lifting. But, putting “may” there is still accurate even if it’s only possible by the victim telling the attacker their email address. 🙂

Is there something here of concern? Possibly. Whether it’s of any REAL concern depends on how much the reporting of this is based on 404media benefiting from the attention by getting new folks to to give THEM their email addresses by signing up for their Free subscription tier or becoming a Supporter or Superfan (dang, that t-shirt at the Superfan level is pretty hard to pass up!) OR because they truly believe that the exploit as it currently exists is dangerous. (Oh, and lets not forget the hits they’re going to get on their ad views)

From their side, it’s either, “Say nothing, allow Apple’s process to continue and protect users around the world by not even saying that it exists all while not turning a profit from the information” OR “Make a profit from the information because the potential for attack is REALLY unlikely, so they’re not really putting anyone at risk”. I’m leaving out the “intentionally putting folks at risk in order to get a quick boost to subscriptions and ad revenue” because there’s no one that would do that, right?
 
Last edited:
Apple don’t care. All they want to do is push people to buy the same devices over and over, by throwing “new features” at us that show up broken and never get fixed, and subscribe to services, like this “service” being shown as broken in this article.
Why do you continue to use Apple products if everything is broken and never gets fixed?

I agree they should fix bugs of course, however no one is "pushing" you to buy the same devices or subscriptions besides yourself. Unless I misunderstood and you're on Android.
 
Last edited:
My guess is that it is something like one or more of these:
...

The key would be for all of those: you get forwarded from Apple's servers to the final destination and then trigger a bounce there which includes the email address. You might be able to do it if you had a server that had a < 20MB attachment limit also so that you could send a 19.99MB attachment which is forwarded through iCloud, then if the limit at the server is 10MB, it is bounced. There seem to be a fair number of ways to trigger a hard bounce which includes the email address at the destination, but this attachment method wouldn't help for gmail since their attachment limit is 25MB.

Maybe it is something completely different though.
 
I mean… it’s not being exploited… even though it, apparently, hasn’t been fixed. FOR A YEAR. ...

I agree they should have fixed it quite quickly, but I don't think we know that it is not being exploited. People could be using it to tie HME to a real address and not advertising that they are doing so. Why would they say anything? And maybe it isn't worth the time for most people. For me, I just use the HME so that I can see where junk is coming from or if it is being sold etc and then can disable it. I'm not using it to hide anything that could put someone in danger: e.g. perhaps leaking from somewhere that could have bodily harm in doing so and then there could be serious consequences. Or perhaps FB or some ad network might want to tie the people together. 🙂
 
This is the kind of thing that seriously undermines any claim that Apple is the “privacy” choice for consumers.
I use “Hide my Email” regularly, so learning about this is really maddening. Apple management obviously doesn’t see it as a serious issue if they allowed it to linger this long. How big of a chunk of salt are expected to bring along when we listen to their ads, like the ones running currently regarding Safari and trackers, for example?
While you are correct in one aspect. I’m not throw the baby out with the bath water type of person.
 
“We don't know why it hasn't been fixed…”

It hasn’t been fixed because Apple don’t fix bugs.

There are countless text editing/entry bugs in iOS/iPadOS that appeared during iOS 18 and were never fixed to this day.

I’m also still suffering corrupt iMessage conversations on iPhone when the addressee has both iMessage on a Mac and RCS on a droid phone, mixed back & forth in a conversation (I can’t send iMessages to ONE person, only, on my iPhone, but it works on all other devices, and the same recipient CAN get iMessages from me in a shared/group conversation on my iPhone). This started in iOS 18, still not fixed. Deleting and creating a new conversation used to correct it in iOS 18 but not in iOS 26. When it fails to send from iPhone, it fails entirely SILENTLY, with no error messages.

I could list countless bugs they’ve never fixed across major OS revisions. Apple don’t care. All they want to do is push people to buy the same devices over and over, by throwing “new features” at us that show up broken and never get fixed, and subscribe to services, like this “service” being shown as broken in this article.
This happened to me just the other day and i thought i was going crazy. Worked fine up until it didnt. However, I was getting the "not delivered" message
 
I've experienced this firsthand and can confirm HME vulnerabilities still haven't been fixed. Really appreciate macrumors covering this because it's not well known by consumers.

There are also numerous ways Hide My Email exposes the real email address. One of the most common is when you send an email with an attachment, the email falsely shows that it was sent via Hide My Email. However when you receive a reply to that email, the header and quoted text clearly show that the recipient received the email from your real email address.

Apple has repeatedly been told about all the bugs and broken security of Hide My Email since its inception, yet they refuse to fix it. Hide My Email is a paid feature so this level of incompetence calls for a class-action lawsuit.
 
Last edited:


A flaw in Apple's Hide My Email service can reportedly allow almost anyone to uncover the real email address behind a generated alias, and Apple has failed to address it for more than a year since it was first reported.

General-macOS-Mail-Feature.jpg

404 Media is withholding the technical specifics of the vulnerability because it remains exploitable, but the publication verified the issue this week using one of its own Hide My Email addresses. In tests with volunteers by the researcher who discovered the flaw, 100% of Hide My Email addresses were found to be exploitable.

Tyler Murphy, co-founder of EasyOptOuts, discovered the issue and responsibly reported it to Apple in June 2025, along with instructions to replicate it. Apple acknowledged the report a month later and said it was investigating. Murphy said:



In March 2026, Apple told Murphy it had "addressed the reported issue in a recent system change," but Murphy found the flaw had not in fact been closed. He provided further information, and Apple replied again to say it was still investigating.

In May, Apple once more said the issue remained under investigation and asked Murphy not to disclose it publicly until the inquiry was complete. Murphy proposed that Apple suspend the creation of new Hide My Email addresses as an interim measure to limit customer risk, but there is no indication that suggestion was acted on. By the end of May, Apple said it expected to address the issue in a security update "expected in the coming weeks."

Hide My Email is an iCloud+ feature that lets users generate random alias email addresses, primarily for use when signing up to services or corresponding with third parties. It is designed to protect a user's real email address from spam, data breaches, and unwanted identification.

Murphy noted that numerous people-search databases are freely available online and can tie an email address to a person's other personal details, meaning anyone depending on Hide My Email for their safety may be more exposed than they realize. Last month, it emerged that Apple's decision to move Hide My Email to a dedicated "private.icloud.com" domain appears to have the consequence of making it easier for platforms that want to block iCloud aliases to do so.

Article Link: Apple Hide My Email Vulnerability Exposes Real Email Addresses

I agree with others above. MR should use some of its clout to more broadly publicize this and get a response from Apple. This is a pretty big hole, especially because most of us weren’t aware of it. Apple should respond with a timeline to fix, or stop calling it “hide my email”.
 
Apple is playing with fire.

I don’t think this is the tipping point, but eventually Apple’s reputation on privacy and security will take a hit. That’s going to be an incredibly expensive reputational loss.
 
  • Like
Reactions: bice
I agree they should have fixed it quite quickly, but I don't think we know that it is not being exploited. People could be using it to tie HME to a real address and not advertising that they are doing so. Why would they say anything? And maybe it isn't worth the time for most people. For me, I just use the HME so that I can see where junk is coming from or if it is being sold etc and then can disable it. I'm not using it to hide anything that could put someone in danger: e.g. perhaps leaking from somewhere that could have bodily harm in doing so and then there could be serious consequences. Or perhaps FB or some ad network might want to tie the people together. 🙂
No one would have to tell anyone anything. If it was being exploited in any real way 404media would be reporting that it’s being done and any other “security researcher” looking to get their name out there would be reporting on it being done. One thing about Apple’s position in the security landscape is, as 404 media well knows, there is real financial value in reporting on Apple exploits, the ones that are fairly unlikely to occur AND the ones that are being actively exploited. There’s a fairly large number of people that would benefit from communicating it to as many folks as possible.

FB and ad networks ARE indeed tying folks together and it’s almost trivially easy for them to do so with the fairly extensive social media wake many people leave behind themselves. In fact the “may” in this story could be related to the fact that companies/malicious actors MAY use it, but there’s so many other more reliable and more effective ways of connecting people that it’s not worth their effort to do it in the way 404media is describing. They “may” do it if they decide they want to do the same thing but with many extra steps with worse output and success rates!
 
Apple is playing with fire.

I don’t think this is the tipping point, but eventually Apple’s reputation on privacy and security will take a hit. That’s going to be an incredibly expensive reputational loss.
Their reputation will take a hit from 404 media? 😉
 
No one would have to tell anyone anything. If it was being exploited in any real way 404media would be reporting that it’s being done and any other “security researcher” looking to get their name out there would be reporting on it being done. One thing about Apple’s position in the security landscape is, as 404 media well knows, there is real financial value in reporting on Apple exploits, the ones that are fairly unlikely to occur AND the ones that are being actively exploited. There’s a fairly large number of people that would benefit from communicating it to as many folks as possible.

FB and ad networks ARE indeed tying folks together and it’s almost trivially easy for them to do so with the fairly extensive social media wake many people leave behind themselves. In fact the “may” in this story could be related to the fact that companies/malicious actors MAY use it, but there’s so many other more reliable and more effective ways of connecting people that it’s not worth their effort to do it in the way 404media is describing. They “may” do it if they decide they want to do the same thing but with many extra steps with worse output and success rates!

My point above was we don't know if it is being exploited because no one doing it would say so.
😎
 
If you are upset about this revelation , I strongly urge you to engage in mediation today to calm down. Find a quiet place, relax, put your iPhone face-down to expose the camera plateau, turn the ringer off, now raise your hands and form the Apple logo with one , a capital P with the other, relax, take a deep breath … speak solemnly and softly … “Pri Va Cy … Pro Tec Tion … Per Fec Tion ”
 
This is very unfortunate. I painstakingly decoupled each of my vendor (Amazon, Target, etc.) accounts to individual HideMy addresses, sandboxing them on a 1 to 1 basis. That way, if there is a data breach, I can easily retire the specific address associated with that particular vendor account and create a new one with minimal effort and no collateral damage. I currently have 81 unique HideMy address that forward to my main iCloud account. Ugh.
i have done the exact same thing. 122 active HideMy addresses.
it has been a good strategy in order to limit any companies who spam or have been compromised. i think i have had 2 such instances in the past one or two years. and doing it this way we can pinpoint where the leak came from. i have instantly deleted my accounts at those two websites.

apple has been reported to combine HideMy and Private Relay. So, im hoping this flaw is fixed and an even better system emerges.
 
  • Like
Reactions: Robert.Walter
Based on the focus on people search databases, my guess is that data aggregators and web trackers are good enough to tie the alias address to other unique characteristics (cross-site tracking cookies, browser dimensions/attributes, etc.) that they are able to associate the Hide My Email address with other unique personally identifiable information, effectively deanonymizing the user.
I have a feeling that is just a red herring that the security reasearcher put out because he is the founder of EasyOptOuts, a service that helps to remove personal data from people search databases. This report kind of feels like an ad for his service.
 
  • Like
Reactions: Robert.Walter
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.