Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
My point above was we don't know if it is being exploited because no one doing it would say so.
😎
My point is that, after reading this, if any security researcher is seeing the attention 404 media is getting, they’d also be parroting it (as there’s zero chance that ONLY 404 media knows this) to get in on some of the clickbait action.

The fact that they’re not, means that this particular level of clickbait is even below the threshold of those security researchers (and it’s not like their threshold is super high).

EDIT: I searched for the vulnerability excluding July 1st and I saw their last “hide my email” vulnerability report was “If you threaten someone from a ‘hide my email’ address and the Federal Government requests that contact information from Apple, Apple will provide that information.” Most certainly an ‘exploit’, but not one that I would expect Apple would do much about!
 
  • Disagree
Reactions: bice
My point is that, after reading this, if any security researcher is seeing the attention 404 media is getting, they’d also be parroting it (as there’s zero chance that ONLY 404 media knows this) to get in on some of the clickbait action.

The fact that they’re not, means that this particular level of clickbait is even below the threshold of those security researchers (and it’s not like their threshold is super high).
It really feels like an ad for the the security researchers who owns a privacy data removal service, they mention people search sites but don't directly hint that it relates to the exploit he reported.
 
  • Like
Reactions: Unregistered 4U
I stopped using iCloud a year ago when suddenly approx 18 000 emails were deleted (randomly) from my account. I did get them back after some calls to Apple, but since then I haven’t trusted them (i decided to switch to Proton instead).
Proton may indeed be better on privacy than Apple, or even than /most/ other providers, but before placing too much trust in them, you may wish to check out what YouTuber "Reject Convenience" has said about Proton.
 
I’ve noticed that if the HME address is forwarding to a custom domain (one hosted with iCloud+, in my case), that domain (after the @ symbol) is visible in the header of emails sent. So if the custom domain is your actual name, it would be visible to the recipient.

I imagine this is expected behavior. Which is why I’ve set HME to forward to an alias iCloud address rather than my custom domain.
 
I mean FFS Apple had access to Mythos, it could patch it in five minutes. It can’t be that difficult.
 
was it fixed with the 26.5.2 updates a couple of days ago? Does anybody know, as I do not use this feature.
 
I’ve been an Apple-Stan for DECADES. DECADES! I was an original partner in the Newton. My retirement is funded by Apple stock I bought at $11. But what the ever living fark? Jaysus farking cherist!
 


A flaw in Apple's Hide My Email service can reportedly allow almost anyone to uncover the real email address behind a generated alias, and Apple has failed to address it for more than a year since it was first reported.

General-macOS-Mail-Feature.jpg

404 Media is withholding the technical specifics of the vulnerability because it remains exploitable, but the publication verified the issue this week using one of its own Hide My Email addresses. In tests with volunteers by the researcher who discovered the flaw, 100% of Hide My Email addresses were found to be exploitable.

Tyler Murphy, co-founder of EasyOptOuts, discovered the issue and responsibly reported it to Apple in June 2025, along with instructions to replicate it. Apple acknowledged the report a month later and said it was investigating. Murphy said:



In March 2026, Apple told Murphy it had "addressed the reported issue in a recent system change," but Murphy found the flaw had not in fact been closed. He provided further information, and Apple replied again to say it was still investigating.

In May, Apple once more said the issue remained under investigation and asked Murphy not to disclose it publicly until the inquiry was complete. Murphy proposed that Apple suspend the creation of new Hide My Email addresses as an interim measure to limit customer risk, but there is no indication that suggestion was acted on. By the end of May, Apple said it expected to address the issue in a security update "expected in the coming weeks."

Hide My Email is an iCloud+ feature that lets users generate random alias email addresses, primarily for use when signing up to services or corresponding with third parties. It is designed to protect a user's real email address from spam, data breaches, and unwanted identification.

Murphy noted that numerous people-search databases are freely available online and can tie an email address to a person's other personal details, meaning anyone depending on Hide My Email for their safety may be more exposed than they realize. Last month, it emerged that Apple's decision to move Hide My Email to a dedicated "private.icloud.com" domain appears to have the consequence of making it easier for platforms that want to block iCloud aliases to do so.

Article Link: Apple Hide My Email Vulnerability Exposes Real Email Address



A flaw in Apple's Hide My Email service can reportedly allow almost anyone to uncover the real email address behind a generated alias, and Apple has failed to address it for more than a year since it was first reported.

General-macOS-Mail-Feature.jpg

404 Media is withholding the technical specifics of the vulnerability because it remains exploitable, but the publication verified the issue this week using one of its own Hide My Email addresses. In tests with volunteers by the researcher who discovered the flaw, 100% of Hide My Email addresses were found to be exploitable.

Tyler Murphy, co-founder of EasyOptOuts, discovered the issue and responsibly reported it to Apple in June 2025, along with instructions to replicate it. Apple acknowledged the report a month later and said it was investigating. Murphy said:



In March 2026, Apple told Murphy it had "addressed the reported issue in a recent system change," but Murphy found the flaw had not in fact been closed. He provided further information, and Apple replied again to say it was still investigating.

In May, Apple once more said the issue remained under investigation and asked Murphy not to disclose it publicly until the inquiry was complete. Murphy proposed that Apple suspend the creation of new Hide My Email addresses as an interim measure to limit customer risk, but there is no indication that suggestion was acted on. By the end of May, Apple said it expected to address the issue in a security update "expected in the coming weeks."

Hide My Email is an iCloud+ feature that lets users generate random alias email addresses, primarily for use when signing up to services or corresponding with third parties. It is designed to protect a user's real email address from spam, data breaches, and unwanted identification.

Murphy noted that numerous people-search databases are freely available online and can tie an email address to a person's other personal details, meaning anyone depending on Hide My Email for their safety may be more exposed than they realize. Last month, it emerged that Apple's decision to move Hide My Email to a dedicated "private.icloud.com" domain appears to have the consequence of making it easier for platforms that want to block iCloud aliases to do so.

Article Link: Apple Hide My Email Vulnerability Exposes Real Email Addresses
Apple’s decision to move Hide My Email to the same subdomain that is used for Signin with Apple will actually have the exact opposite effect than that some sites like this one claim, and could be part of mitigation of what this article is about.

By moving HideMyEmail to the same subdomain that other randomly generated email addresses are created in, user privacy is enhanced because sites can no longer tell if an “odd looking” iCloud email is from Hide My or if it’s something else
 
  • Like
Reactions: bice
It’s a feature for law enforcement convenience. Apple has plenty of those, including the one where you can’t hide the first character of your iPhone password when you type it. 😉
 
  • Wow
Reactions: gusmula
This is the kind of thing that seriously undermines any claim that Apple is the “privacy” choice for consumers.
I use “Hide my Email” regularly, so learning about this is really maddening. Apple management obviously doesn’t see it as a serious issue if they allowed it to linger this long. How big of a chunk of salt are expected to bring along when we listen to their ads, like the ones running currently regarding Safari and trackers, for example?
How dare you questioning Apple’s commitment to Privacy Protection!! 😉
 
I’ve noticed that if the HME address is forwarding to a custom domain (one hosted with iCloud+, in my case), that domain (after the @ symbol) is visible in the header of emails sent. So if the custom domain is your actual name, it would be visible to the recipient.

I imagine this is expected behavior. Which is why I’ve set HME to forward to an alias iCloud address rather than my custom domain.
Then why still have a custom domain? The HME addresses have to forward to somewhere
 
Then why still have a custom domain? The HME addresses have to forward to somewhere
I still use the custom domain for recipients I trust. For HME, I use an iCloud domain address as the forward to address.

I imagine that most people might think the original sending address is completely hidden when using HME. It’s not. The domain portion is visible in the header to the recipient. Apart from this news, it’s not a problem if the original address is iCloud or Gmail. But it could be if an HME user is trying to completely hide a custom domain.
 
  • Like
Reactions: bice
I agree with others above. MR should use some of its clout to more broadly publicize this and get a response from Apple. This is a pretty big hole, especially because most of us weren’t aware of it. Apple should respond with a timeline to fix, or stop calling it “hide my email”.
That will never happen because they fear Apple like a lot of western media outlets.

They fear being left out in the cold and not getting invites to events.

There are lots of people who spoke out about apple flaws or bugs and then get blacklisted, meanwhile Google and Samsung get abused for lesser errors or bugs because they don't rule with an iron fist.

Apple marketing is truly a nasty lying snide of an operation.
 
  • Haha
Reactions: I7guy
This is very unfortunate. I painstakingly decoupled each of my vendor (Amazon, Target, etc.) accounts to individual HideMy addresses, sandboxing them on a 1 to 1 basis. That way, if there is a data breach, I can easily retire the specific address associated with that particular vendor account and create a new one with minimal effort and no collateral damage. I currently have 81 unique HideMy address that forward to my main iCloud account. Ugh.
Me too, I am using unique HideMyEmail addresses for all websites and logins, 407 by now. I only wish you could see the actual "label" (e.g. website name) on top of Apple Mail email view instead of just "To: Hide My Email"
 
Funny how easily some discard the reporting based on not finding data on the flaw by searching or "if it was real others would have posted about it"

So if a serious bug hunter does the right thing and only contacts Apple and don't disclose it for others, then they cannot be trusted, not until mighty Apple goes public after a fix is issued.

The logic is clear, if you find a security flaw, report to Apple and then secretly sell the attack vector to malicious actors. Then document the flaw is exploited, put pressure on Apple by leaking the info to other security researchers but not to macrumors and wait for Apple to fix and pay the bounty. Then sell the story to macrumors how you help mighty apple fix it and finally collect street cred from online apologists.
 
I ran a test of HME against Gmail earlier today ("Hello. This is a test. Etc.etc.") and looked at the headers and routing information. Not seeing anything, the headers are remarkably clean.
 
Funny how easily some discard the reporting based on not finding data on the flaw by searching or "if it was real others would have posted about it"

So if a serious bug hunter does the right thing and only contacts Apple and don't disclose it for others, then they cannot be trusted, not until mighty Apple goes public after a fix is issued.

The logic is clear, if you find a security flaw, report to Apple and then secretly sell the attack vector to malicious actors. Then document the flaw is exploited, put pressure on Apple by leaking the info to other security researchers but not to macrumors and wait for Apple to fix and pay the bounty. Then sell the story to macrumors how you help mighty apple fix it and finally collect street cred from online apologists.
Is 404 media a cybersecurity research firm? Or, are they an independent digital media company that gets rewarded by creating headlines that gets them attention and subscribers? The logic is clear, report clickbait, get money.
 
There are lots of people who spoke out about apple flaws or bugs and then get blacklisted

Mods blacklisting posters for criticizing Apple's flaws? That has not been my experience. You're making comments like "Apple marketing is truly a nasty lying snide of an operation" and you've survived almost 10 years...

This is probably the single biggest gathering of Apple customers, and MR regularly reposts information that Apple sues the original sources over. I don't think the problem is MR being worried about Apple putting them on the naughty list for asking a question, but I'm not sure MR is set up to original reporting.
 
Prove it. At the moment it sounds like an accusation that may be very hard to exploit. Someone at macrumors should post a hide my email address and ask for it to be decoded. It has to be anonymous, for example I could not post one as it would be easy to reverse engineer my iCloud email from social media.
 
  • Like
Reactions: Unregistered 4U
Mods blacklisting posters for criticizing Apple's flaws? That has not been my experience. You're making comments like "Apple marketing is truly a nasty lying snide of an operation" and you've survived almost 10 years...

This is probably the single biggest gathering of Apple customers, and MR regularly reposts information that Apple sues the original sources over. I don't think the problem is MR being worried about Apple putting them on the naughty list for asking a question, but I'm not sure MR is set up to original reporting.
I didn't say posters on this forum, I was talking about people in actual tech media.

 
I didn't say posters on this forum, I was talking about people in actual tech media.


Apple PR can choose who they forge relationships with. Maybe they stopped working with him because he put out a bad review, or maybe because it wasn’t a website that pulled a ton of traffic and wasn’t worth their time. MacRumors’ purpose is to publish information daily that Apple doesn’t want published and they still get invited to events. Probably because, as I said, this is the single largest gathering of Apple users. MR should use that clout in situations like this.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.