Updated
Updated · 404 Media · Jul 21
Apple Patches iCloud+ Email Flaw After 1 Year, Facing Class Action
Updated
Updated · 404 Media · Jul 21

Apple Patches iCloud+ Email Flaw After 1 Year, Facing Class Action

3 articles · Updated · 404 Media · Jul 21

Summary

  • July 3 marked Apple’s patch for a Hide My Email flaw that could reveal users’ real addresses, a fix the company confirmed after 404 Media reported the issue.
  • June 2025 was when researcher Tyler Murphy first alerted Apple; he later found the bug still worked, and limited tests showed 100% of sampled Hide My Email addresses were exploitable.
  • Spam rejections triggered the leak: sending a message that got bounced could expose the linked real address, and Murphy said affected users may never have seen those messages in their inboxes.
  • Murphy and EasyOptOut warned the risk may linger because mail-transfer logs are often retained, so aliases created before July 7, 2026 may already have been exposed in third-party records.
  • A proposed class action now seeks refunds for iCloud+ subscription costs tied to the feature and an injunction over what it calls Apple’s deceptive conduct.

Insights

A lawsuit claims Apple's privacy feature failed. Were millions of users' real emails exposed for over a year?
After a year-long delay to fix a critical privacy bug, can Apple still be trusted with your data?
The email bug is patched, but are your old 'hidden' addresses still traceable in third-party server logs?