Apple's Hide My Email Has Been Leaking Real Addresses for Over a Year
Apple's Hide My Email is supposed to keep your real address secret. A researcher found any alias can be traced back to your Apple account, reported it over a year ago, and it still is not fixed. As of this week, it still works.
If you pay Apple for Hide My Email to keep your address private, there is a problem: the feature leaks the one thing it is meant to hide. A researcher found a way to take one of those random @icloud.com aliases and resolve it straight back to your real email address and Apple account. He told Apple over a year ago. It still is not fixed, and as of this week it still works.
Quick refresher for anyone who doesn't use it. Hide My Email is part of paid iCloud+. It generates throwaway addresses, almost always two random words and a number at @icloud.com, that forward to your real inbox. People use it to cut spam, to keep certain accounts from linking back to their identity, to make a throwaway for a signup that might get breached later, and so that a stolen password does not come bundled with a live address that is really yours. The whole idea is that the alias and the person behind it stay completely unconnected.
That connection is exactly what broke. Tyler Murphy, co-founder of EasyOptOuts, found and reported the vulnerability. 404 Media tested it the obvious way: a reporter generated a fresh Hide My Email alias and handed it over, and about five minutes later Murphy came back with the real address behind it. 404 Media also had volunteers throw aliases at the flaw, and every one of them was exploitable. Murphy put it at 100 percent.
Neither 404 Media nor the researcher is publishing how it works, because it is still live. That is the uncomfortable part. This is not a patched bug being written up after the fact. It is a working way to de-anonymize people, running right now inside a feature people specifically choose for protection.
The timeline is what makes it worse. Murphy first reported it to Apple in June 2025. Apple acknowledged it in July and said it would look into a fix. In March 2026 Apple said it had shipped a fix in a recent system update, except it had not, and Murphy showed them the exploit still worked. He sent more detail. Apple said it would keep investigating. In May, Apple asked him to hold off on disclosing anything until it was done, and Murphy asked back whether Apple would at least stop selling the feature to new customers while it was broken. Late in May, Apple told him a fix was coming in a security update in the next few weeks. Those weeks passed. Murphy went to 404 Media instead, saying he did not feel comfortable waiting any longer. Apple did not respond to requests for comment.
Here is why a leaked alias actually hurts. On its own, an email address is not much. But free people-search sites will happily take that address and staple it to a name, a location, old breach records, and whatever else they have hoovered up. So the moment an attacker turns your alias back into your real @icloud.com address, they can often walk it straight into the rest of your life. If you use Hide My Email to cut spam, that is annoying. If you use it because you need distance from a stalker, an abusive ex, or anyone who simply should not be able to find you, that is a different order of problem.
And the feature is getting squeezed from the other side at the same time. In June, Apple told developers it is moving generated addresses off @icloud.com onto a new @private.icloud.com domain in the coming weeks. The reason Hide My Email works today is that its aliases look identical to any normal iCloud address, so sites cannot pick them out. Put a dedicated private domain on them and any site or app can spot a Hide My Email signup on sight and block it. Existing addresses keep forwarding, but the very thing that made the feature useful gets quietly stripped away. One hand is leaking the addresses while the other makes them easier to fingerprint.

If you rely on Hide My Email
You do not need to burn all your aliases tonight. You do need to stop treating Hide My Email as a hard anonymity guarantee, because right now it is not one.
- Spam and convenience: carry on, eyes open. The aliases still forward and still keep clutter off your main inbox. Just do not lean on one as your only shield for anything you truly need kept away from your name.
- Safety-critical use: do not rely on it alone. If being found could have real consequences, build a fully separate identity for that, a different email provider and an account that is not tied to your Apple ID, ideally on a device and number that are not tied to you either.
- Line up a fallback for the domain change. Once your aliases move to @private.icloud.com, expect more sites to reject them at signup. Have another address ready for the services you actually care about.
- Assume the leak is exploitable until a fix is confirmed independently. Apple has already claimed once that it was fixed when it was not, so wait for a third party to check, not just an Apple note, before you trust it again.
The thing to sit with: this is a paid privacy feature that has been failing at the single job it advertises, for more than a year, while the vendor knew. If any part of your safety plan rests on one vendor's promise, take this as the nudge to put a second layer underneath it.