For months, the real address behind Apple's alias feature could be exposed – now Apple has declared the leak closed. The patch was released on July 3rd, but the issue isn't completely resolved. Those using iCloud+ should keep one point in mind.
Apple's iCloud+ feature "Hide My Email" is designed to prevent the exact opposite of what a recently discovered bug made possible: instead of protecting the real address, a security vulnerability allowed the actual address to be revealed behind an alias. After more than a year and several failed attempts, Apple has now officially declared the problem fixed.
What the gap revealed
The function generates random disposable addresses - two words, a sequence of numbers, and the icloud.com domain - that forward incoming messages to the actual mailbox. This very mapping could be uncovered under certain conditions: The real address appeared in mail logs, for example, when a message was rejected or marked as spam. Only the alias level was affected - passwords and the Apple account itself were not exposed.
It's impossible to quantify how often genuine email addresses were actually leaked. Since the leak could be triggered by an automatically rejected email, such messages often never even reached the inbox – so checking the spam folder is no way to determine if you've been affected.
A fix with a long history
The vulnerability was first reported in June 2025 by Tyler Murphy, co-founder of the EasyOptOuts service. Apple acknowledged receipt of the report and declared the problem resolved in March 2026 – but further testing revealed it could still be exploited. Another attempt to fix it at the end of June also failed. It wasn't until the magazine 404 Media publicly revealed the still-open vulnerability in early July that things started moving: On July 3rd, Apple released the patch, which the company now describes as a complete fix.
The technical details were only released now because the vulnerability can no longer be exploited. However, a degree of skepticism remains warranted – after all, Apple had previously declared the vulnerability closed, even though it wasn't.
What iCloud+ users should know now
The fix is implemented server-side and therefore takes effect automatically – no update is necessary for iCloud+ and Apple One customers in Germany, Austria, and Switzerland. However, there is a catch: addresses created before July 7, 2026, may already be logged by third-party providers and still stored there. The patch prevents new leaks but does not reverse previous ones.
For particularly sensitive logins, you can create new alias addresses to start cleanly separated from past ones. Those who want to generally secure their iCloud data more strongly can also activate the strongest encryption level for iCloud.
Apple's privacy promise is under scrutiny
A class-action lawsuit is also underway: Anthony Alvarez filed it on July 15 in the U.S. District Court for the Northern District of California, accusing Apple of misleading advertising, fraud, and breach of contract. He is seeking damages, a refund of subscription fees, and a court order. So far, no actual attack exploiting the vulnerability has been proven. A feature that markets advertising as privacy protection loses its value as soon as the hidden address can be traced – therefore, it will likely be closely watched whether the fix holds this time. (Image: Apple)
- Apple patent: Future iMac could get a carrying handle and dock
- Women in Blue: Apple TV shows the trailer for the second season
- iOS 26.6 prepares the iPhone for iOS 27
- TSMC raises chip prices: Apple could become more expensive
- iOS 27 Beta 4: All new features at a glance
- App Store: New apps are doubling, downloads are stagnating
- iPhone Ultra: Code in iOS 27 Beta 4 suggests two batteries
- Live Notes: AI at the Genius Bar raises surveillance concerns
- Why Apple is keeping Jony Ive out of the OpenAI lawsuit
- M2 Extreme and M3 Extreme: Apple's discontinued Mac Pro chips
- iPhone Ultra: Apple ramps up steam chamber orders
- iPad mini 8 with OLED: Apple aims for October market launch



