foreign media 404 Media Recently revealed, Apple iCloud+’s “Hide My Email” feature has an unpatched security vulnerability that could potentially expose users’ real email addresses under certain conditions. This vulnerability was discovered by a security researcher Tyler Murphy He discovered that he had already reported it to Apple last year, but the issue still hasn’t been completely fixed.

iCloud “Hide My Email” Feature Has a Bug, Real Address Can Be Exposed
According to reports, while 404 Media has not disclosed the technical details of the vulnerability, multiple tests have confirmed that users’ real iCloud email addresses may still be exposed behind anonymous addresses generated through “Hide My Email.” Following standard security practices, researchers typically only release such information after a vulnerability has been patched to avoid causing greater risk. However, since Apple has repeatedly failed to address the issue and the vulnerability has persisted for a year, Murphy ultimately chose to go public, hoping to prompt Apple to accelerate the fix.

Murphy says that a month after he first reported the vulnerability, Apple told him the issue had been fixed. However, after updating, he was still able to successfully reproduce the vulnerability and provided Apple with more details again. Last May, Apple replied that they were still investigating the issue, but subsequently did not provide any clear progress. The vulnerability remains unfixed, raising questions about the privacy protection effectiveness of Hide My Email.

“Hide My Email” is one of the flagship features of iCloud+, allowing users to create anonymous email addresses when signing up for websites or apps to avoid exposing their real identity. According to Apple, these randomly generated addresses are used solely for services to contact users, with all emails forwarded to the user’s primary iCloud account, while senders cannot see the actual address. Precisely because of this, the feature is popular among privacy-conscious users.
However, until the vulnerability is patched, users should remain vigilant. While the functionality still works, the privacy protection may not be as reliable as expected. If you have concerns about the security of anonymous email services, you can temporarily use alternatives, such as creating a secondary email account on free email services like Gmail or Yahoo specifically for registering non-essential accounts, until Apple officially fixes the issue.

It’s worth noting that Apple recently announced it will be adjusting the domain format for Hide My Email. Future newly created private addresses will use @private.icloud.com instead of the previous @icloud.com. This change may cause some websites or services to refuse to accept registration emails because they don’t recognize the new domain. Apple said the new domain will officially launch later this summer but did not clarify whether this update is directly related to the vulnerability exposed by Murphy. Overall, this incident highlights the complexity involved in designing and maintaining privacy tools, and serves as a reminder that even security features from major tech companies can still pose risks. Apple has not yet provided a clear timeline for a fix, and in the meantime, users will have to weigh the trade-off between convenience and privacy protection on their own.
Source: KOCPC Chinese