Apple's Hide My Email is one of the most widely used email alias tools in the world, bundled straight into iCloud+ and "Sign in with Apple". The entire promise is simple: generate a random address, give that out instead of your real one, and Apple quietly forwards everything to your actual inbox without anyone else ever seeing it.
A researcher found a way to break that promise over a year ago. It's still not fixed.
What's actually confirmed
Security researcher Tyler Murphy, co-founder of EasyOptOuts, discovered a flaw that lets someone take a Hide My Email address, the random string you'd hand out to a website or app, and get Apple's own systems to disclose the real address behind it. When 404 Media tested it independently, they reported that essentially every Hide My Email address they tried was exploitable.
We're deliberately not explaining how it works. The exact technical method hasn't been published, including by the researchers who found it, because it's still unpatched. Publishing it would just hand out a working exploit. What's confirmed publicly is the outcome: given a Hide My Email address, Apple's systems can be made to reveal the real one behind it.
The timeline
Murphy reports the issue to Apple, with instructions to reproduce it.
Apple acknowledges the report and says it's investigating.
Apple tells Murphy the issue was "addressed in a recent system change." Murphy tests it again. It isn't fixed.
Apple says the issue remains under investigation and asks Murphy not to disclose it publicly, citing a security update expected "in the coming weeks."
Still unpatched. 404 Media publishes, after verifying the flaw themselves.
That's over a year between the first report and public disclosure, with at least one claimed fix along the way that turned out not to work.
A separate, older weak point: replying from the wrong client
Independent of this specific vulnerability, Hide My Email has a longer-standing design limitation worth knowing about. The privacy trick, keeping your real address hidden even when you reply to a forwarded message, depends partly on Apple Mail or iCloud handling that reply specially. If you reply to a Hide My Email-forwarded message from a different mail client or a different provider entirely, your real address can end up exposed in that reply, not because anything is broken, but because the protection was never fully provider-independent to begin with.
What this means if you use Hide My Email
- You can't fully protect yourself against the current bug. It's server-side, so there's no setting to change or workaround to apply. Whether a given address gets targeted is out of your hands until Apple ships a real fix.
- Be more careful what you reply to, and from where. If you use a Hide My Email address for something sensitive, reply from Apple Mail or iCloud specifically rather than another client, to avoid the separate, older exposure risk above.
- Consider not putting everything behind one company's alias system. If your entire alias strategy runs through one provider's infrastructure, a flaw like this one affects all of it at once. Spreading sensitive sign-ups across more than one alias source limits how much a single bug can expose.
The point here isn't "Apple bad." Every company that stores or forwards personal data will have bugs at some point, Apple included. The real question is how a provider behaves once a bug like this is found, how quickly it gets fixed, and how transparent it is while that's happening. A year with a claimed fix that didn't work is a fair thing to weigh when deciding how much of your identity sits behind any one system.
Where Privify fits
We can't promise you a service with zero bugs, ever, no one honestly can. What we can tell you is how we're built: email aliases and forwarding run on our own infrastructure, hosted in the EU, independent of Apple's, Google's, or anyone else's ecosystem. If a flaw is ever found in how we handle your data, we'll tell you directly and fix it, the same way we've handled every issue on our own status updates so far.
Using a Hide My Email address for your Apple ID itself makes sense, since Apple built it for that. But for everything else, having an alias provider that isn't the same company running the rest of your digital life is a reasonable piece of security hygiene, not paranoia.
Keep your aliases somewhere else
Private email aliases from a UK-based, EU-hosted provider, independent of any single tech ecosystem. Forwarded straight to your existing inbox.
Get started, from £1.99/month →