Apple closed the vulnerability that exposed users’ real email addresses in the iCloud+ Hide My Email feature with the patch it released on July 3.
Apple has fixed a security vulnerability that allowed users’ real email addresses linked to their Apple accounts to be learned by others. The company announced that it completely solved this problem with the patch released on July 3.
The vulnerability in question is included in Apple’s paid subscription services iCloud+ and Apple One. Hide My EmailIt affected its properties. This feature allows users to create random and anonymous email addresses to keep their real email addresses implicit.
How did the vulnerability emerge?
The Hide My Email feature was developed especially for users who do not want to share their personal email address when registering on websites or online services. However, the information shared by 404 Media that revealed the real addresses behind these pseudonyms could be viewed by everyone due to a vulnerability in the system.
This situation also caused a lawsuit to be filed against Apple as it directly affected users’ implied rights. Apple confirmed that the security vulnerability has been closed and stated that no one can now access a user’s personal e-mail address with this formula.
How did the process work?
Security researcher Tyler Murphy first reported the issue in question to Apple in June 2025. Although Apple stated that it had fixed the problem in the first phase, Murphy found that the security vulnerability was still active in the system.
The company announced that it has completely eliminated this security vulnerability with the latest updates. This step to protect users’ personal data is of great importance, especially today, when digital privacy is at the forefront.
Such security patches offered by Apple play a critical role in keeping subscribers’ data safe. What do you think about this security development?