After a Year, Apple Closes Privacy Feature Vulnerability and Faces Lawsuit
Apple released a software update to fix a vulnerability in the 'Hide My Email' service that allowed real addresses to be exposed. Despite the fix, the discoverer warns of ongoing risks, amid a class-action lawsuit accusing the company of deception.
Apple fixed a security flaw in the paid 'Hide My Email' service that caused users' real addresses to be leaked, even though the service's feature is designed to hide them to enhance privacy.
This step comes at a time when pressure is mounting on tech companies to strengthen user data protection.
Since 2021, the feature has been generating temporary email addresses for site registrations, forwarding messages to the primary account without revealing it.
The report stated that Apple released an update on July 3 that completely closed the vulnerability. Prior to that, the real email could be exposed by sending a spam message to a fake address, which would be automatically rejected, leading to the original being leaked in some cases.
Even after the fix, security researcher Tyler Murphy, who discovered the vulnerability, warned that the risk remains, noting that some regular messages might also be rejected and that server logs may retain previously exposed addresses.
Murphy added that any email address linked to Hide My Email created before July 7, 2026, may have already been exposed and might still be stored in third-party logs, potentially limiting the protection the feature provides.
According to the report, Murphy first informed Apple of the vulnerability in June 2025. After months of investigation, the company confirmed it had fixed the issue, but he later managed to re-expose the hidden addresses, prompting Apple to reopen the investigation.
When Apple did not complete the fix, Murphy reached out to 404 Media to disclose the vulnerability without technical details.
This incident comes as Apple relies on privacy as a key pillar of its product and service marketing, making the vulnerability spark widespread criticism, especially since it affected a paid feature intended to protect user data.
In a related development, tech site PCMag reported that Apple faces a class-action lawsuit accusing it of deceptive practices regarding the Hide My Email feature, seeking to compel the company to rectify these practices and refund subscription fees paid by customers.
Tags
Hide My Mail Apple
Link copied
July 23, 2026 Last updated: July 23, 2026
One minute
Follow us
Apple heavily relies on privacy as a marketing cornerstone for its products, making any vulnerability in this feature a blow to its image. The vulnerability persisted for over a year despite being reported to the company, raising questions about the effectiveness of security audits. The class-action lawsuit could lead to compensation or changes in Apple's policies. Moreover, Murphy's warning that exposed addresses remain in external logs reduces the effectiveness of protection even after the fix. Users should update their accounts or create new addresses to ensure privacy.
Original source: AIT News
Comments (0)
Be the first to comment.