Apple Hide My Email Flaw Exposes Addresses
Coverage from CNET, PCMag, and others

Apple’s iCloud+ Hide My Email feature was reported to contain a vulnerability that could let websites, senders, or other parties associate masked email aliases with users’ real addresses.
Apple says it deployed a fix in July 2026, but researchers and lawsuit filings describe earlier fixes as incomplete and warn that previously exposed addresses may remain in third-party logs. The disclosure has also prompted proposed class-action litigation alleging that Apple marketed a privacy feature that did not reliably protect users’ identities.
The main update is a reframing of the flaw as still potentially exposing identities through third-party email-processing data, even after Apple’s July 2026 patch. The current version also tightens the litigation framing and drops earlier claims about broad exploit testing and the planned alias-domain migration as central elements.
The biggest change is that Apple now says it shipped a patch on July 3, 2026, turning the story from disputed vulnerability reports into a confirmed remediation timeline. The legal and reputational stakes also sharpened as new proposed class actions framed the issue as misleading privacy marketing.
