Recently 404 Media reported on a vulnerability with the iCloud+ ‘Hide My Email’ feature that allowed anyone to access a user’s real email address. Now, Apple says the issue has officially been fixed.
Hide My Email security bug was patched earlier this month, says Apple
If you’re an iCloud+ or Apple One subscriber, Apple offers a ‘Hide My Email’ privacy feature that can be especially handy for protecting your real email.
Here’s how it works, per Apple’s website:
Hide My Email lets you generate unique, random email addresses that automatically forward to your personal inbox — and even let you reply — so you don’t have to share your real email address when filling out a form on the web or signing up for a newsletter.
But per the recent 404 Media report, a bug has long existed in Hide My Email that lets anyone expose the real email address tied to the Apple account. This revelation sparked a new proposed lawsuit.
Today though, Apple says the vulnerability was officially fixed earlier this month.
Apple told 404 Media that it “deployed a patch for the issue on July 3, which the company says has fully resolved the issue.”
The iCloud+ vulnerability was first reported to Apple in June 2025 by Tyler Murphy. After an initial exchange in which Apple claimed to have fixed it, Murphy found the issue still existed. Hopefully this time around though, the problem has truly been taken care of.
How often do you use the Hide My Email feature with iCloud+? Let us know in the comments.
Best iPhone accessories
FTC: We use income earning auto affiliate links. More.