Hide My Email has one job. You hand a website a made-up address, Apple forwards the mail, and the address you actually live at stays out of every database that later gets breached, scraped or sold. For more than a year, a bounced email could undo the whole arrangement.
Apple patched the flaw on 3 July. The report that forced the issue landed in June 2025. The gap between those two dates is the story.
What the Bug Actually Did
Tyler Murphy, co-founder of the data-removal service EasyOptOuts, found that mail sent to a Hide My Email alias could expose the real address behind it. When a message got rejected as spam, the rejection data included the user’s genuine email address, which then sat in the logs of whoever sent the message. 404 Media, which broke the story publicly earlier this month, reported that on many major email hosts the leak fired on any automatic spam rejection, including messages that were entirely legitimate.
Notice what is missing from that description: an attacker. Nobody had to compromise anything. A spam filter doing its ordinary job was enough to hand over the one piece of information the product exists to protect.
The Timeline Is Worse Than the Bug
Murphy reported the flaw to Apple in June 2025. In March 2026, Apple told him it was fixed. It was not. The working patch arrived on 3 July 2026, days before 404 Media published, and Apple’s guidance is that aliases are only properly safe for mail sent after 7 July. Thirteen months from report to repair, with a false all-clear in the middle.
The false all-clear is the part I keep coming back to. Slow fixes happen; security teams triage, and an obscure bounce-handling bug is easy to lose behind flashier work. Telling the researcher it was fixed in March when it demonstrably was not is a different category of failure, and it is the kind courts get interested in. Apple is already facing a lawsuit over the gap between the marketing and the behaviour, seeking class-action status under California’s false advertising law.
For context on the marketing: Apple spent part of that thirteen-month window running a new privacy campaign with Safari at the centre. The billboards write themselves.
What You Can and Cannot Do About It
The uncomfortable bit: the leak lived in other people’s logs. If one of your aliases bounced a message at any point between June 2025 and early July, your real address may already sit in a sender’s records, and no Apple patch reaches into those. There is no notification coming, because Apple has no way of knowing which addresses leaked where.
So treat it the way you would treat any suspected exposure. For anything sensitive, a bank, a broker, an account you would hate to see credential-stuffed, generate a fresh alias and retire the old one. Keep the real address for people, not services. The logic is the same as hiding your IP address: the mask only earns its keep if it never slips, and this one slipped for a year.
Privacy groups have been circling Apple on exactly this theme for a while. The EFF spent last winter pressing Apple and the rest of big tech to switch on full encryption by default, on the argument that privacy features which fail quietly are worse than no feature at all. Hide My Email just spent thirteen months proving the point.
Does an incident like this change how much weight you put on Apple’s privacy promises, or do you file it under bugs happen and carry on using the alias? And if you have been running Hide My Email since before July, will you rotate the addresses that matter?
- iPhone Ultra: Who Apple Is Actually Selling a Folding Phone To - August 10, 2026
- Carrier Deals to Expect on iPhone 18 Launch Day, and Which Ones Are Traps - August 8, 2026
- Which iPhones Lose Support When iOS 27 Ships - August 7, 2026