🟡 Medium | Source: The Hacker News
Apple has patched a flaw in its Hide My Email privacy feature that caused users’ real email addresses to be leaked into Mail logs, undermining the anonymisation the service is designed to provide. The vulnerability was discovered by Tyler Murphy of EasyOptOuts and disclosed to Apple over a year before a fix was deployed on 3 July 2026. Anyone relying on Hide My Email to mask their identity from senders or services could have had their actual address exposed.
Security Architect’s Take: If your organisation or users rely on Apple’s Hide My Email for privacy-sensitive communications — for instance, as part of a BYOD or privacy-by-design strategy — ensure all Apple devices and iCloud-connected mail clients are updated to receive the patch. Review any logging pipelines that ingest Apple Mail logs for potential historic exposure of real user addresses.
Original advisory: Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs