Apple Patches iCloud+ Email Flaw After 1 Year, Facing Class Action
Updated
Updated · 404 Media · Jul 21
Apple Patches iCloud+ Email Flaw After 1 Year, Facing Class Action
3 articles · Updated · 404 Media · Jul 21
Summary
July 3 marked Apple’s patch for a Hide My Email flaw that could reveal users’ real addresses, a fix the company confirmed after 404 Media reported the issue.
June 2025 was when researcher Tyler Murphy first alerted Apple; he later found the bug still worked, and limited tests showed 100% of sampled Hide My Email addresses were exploitable.
Spam rejections triggered the leak: sending a message that got bounced could expose the linked real address, and Murphy said affected users may never have seen those messages in their inboxes.
Murphy and EasyOptOut warned the risk may linger because mail-transfer logs are often retained, so aliases created before July 7, 2026 may already have been exposed in third-party records.
A proposed class action now seeks refunds for iCloud+ subscription costs tied to the feature and an injunction over what it calls Apple’s deceptive conduct.