A security vulnerability in Apple’s Hide My Email service allows unauthorized parties to uncover users' real email addresses, despite the company being notified of the flaw over a year ago.
Key Points
- Researcher Tyler Murphy discovered the flaw and first reported it to Apple in June 2025.
- Testing confirmed that 100% of Hide My Email aliases are currently vulnerable to identification.
- Apple acknowledged the issue multiple times but failed to implement a functional fix by May 2026.
- The vulnerability exposes users to potential doxxing, as revealed email addresses can be linked to personal data via public people-search databases.
- Apple has not suspended the creation of new aliases despite requests from the researcher to limit user risk.