The images in this article were generated with artificial intelligence. How we publish
Apple has deployed a correction for a vulnerability in its Hide My Email service that, according to published research, could allow real mail addresses to be revealed through mail transfer records when messages addressed to alias generated by Hide My Email were rejected as spam. The story, originally spread by 404 Media and revealed to the public after a period in which Apple tried to park it, calls into question a central promise of the function: to offer disposable aliases that protect the user's identity while filtering unwanted mail. That a payment service designed to hide personal identifiers could filter the real address into technical records is, in practical terms, a loss of the privacy guarantee that many users assumed. 404 Average
The problem, according to the sources that did the public research, was not a theoretical failure but an operational condition: by sending a message that was automatically rejected as spam by certain suppliers, the real address associated with the alias could appear on intermediate mail logs. These records are not in the direct control of the recipient, and therefore an affected person could not easily find out if his address had been filtered through spam folders or his inbox. The exposure was based on metadata processed by mail servers and not on a visible error in the user interface.

The chronology is relevant for assessing responsibility and risk: the ruling was reported to Apple in June 2025, the company tried unsuccessful patches in March and again on June 30, 2026, and finally applied a correction in early July 2026. This delay is also the focus of a collective demand that accuses Apple of advertising a privacy function for which it charges (via iCloud +) and of not having informed customers or mitigated the risk in a timely manner. When privacy services are offered as a product, transparent communication on failures that may affect user confidence is expected.. More information about iCloud + and the features it includes is available on the official Apple page. https: / / www.apple.com / icloud / icloud-plus /
From a technical and risk point of view, there are nuances: that an address appears in server logs does not automatically imply that external attackers have access to these records; however, vulnerability opens vectors for targeted attacks and for scenarios where actors with access to mail infrastructure (or suppliers that do not manage their records well) can correlate real aliases and addresses. At worst, an actor with access to transfer records could deliberately deannimize users, and in other scenarios the incident may have facilitated more accurate spam or phishing campaigns.
For affected or concerned users, caution and speed should be exercised. First, consider rotating any Hide My Email alias created before 7 July 2026 and replace it with a new one; even if Apple has patched the failure, the old aliases could have been registered in logs and there is no guarantee that such records are not kept in other systems. Second, review the accounts associated with these emails by unusual activity, activate authentication of two factors when available and change passwords if you detect suspicious access. Third, if you use Hide My Email for critical accounts (banking, work, password recovery), consider updating contact addresses and, if appropriate, notify relevant mail change services.

Organizations and administrators should also note: the confidentiality of aliases and mail metadata is as robust as the complete delivery chain. Auditing mail providers, reviewing log retention policies and requiring contractual guarantees on the processing of records are necessary steps for those who depend on alias as privacy control. For users looking for additional alternatives or layers, there are alias and mail forwarding services with a privacy focus that allow greater control over the rotation and removal of aliases; it is recommended to evaluate options and understand the operational trade-offs. A couple of examples of specialized services are available on their official pages. https: / / easyoptouts.com
From the legal and reputational point of view, Apple faces a challenge: in addition to collective demand, the company must regain confidence by explaining what failed, why it took so long to remedy it and what compensation or remediation steps it will offer to potentially affected users. Transparency is key for users to retrust that a privacy service meets what it promises. In the ecosystem of digital privacy, the perception of security is as critical as technical security itself.
For those who wish to deepen good technical practices on aliases and mail forwarding, as well as privacy recommendations, it is appropriate to consult sources that explain the management of SMTP records and log retention policies, as well as Apple's official documentation on privacy and security. Keeping informed and implementing proactive controls reduces the impact of future incidents and requires suppliers to improve practices. https: / / www.apple.com / legal / privacy /
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...