Skip to content
logo The magazine for digital lifestyle and entertainment
Apple E-Mail News Security All topics
iCloud+ Error

Apple Closes Security Flaw in Email Service

iCloud login page on a laptop
Apple Promises Anonymous Email Addresses with iCloud+—Reality Tells a Different Story Photo: Getty Images
Share article
Adrian Mühlroth

July 22, 2026, 1:45 pm | Read time: 3 minutes

With an iCloud+ subscription, Apple users receive several benefits over the basic offering. One of these is the “Hide My Email” feature. This allows users to sign up for apps and websites with randomly generated email addresses. It is intended to maintain user anonymity–but it hasn’t always worked reliably. A flaw led to private email addresses being visible. Now, Apple has closed this security gap.

Hidden Addresses Freely Visible

“Hide My Email” is integrated into “Sign in with Apple” and gives users the option to create an anonymous email address when signing up. Where login with Apple isn’t possible, users can simply generate an address along with a secure password and save it in the Passwords app. The generated addresses usually consist of two random words, a number, and the suffix “@icloud.com.” Emails are forwarded to the real address and appear as usual in the inbox.

However, as “404 Media” reported in early July, the real address could still be discovered. This was found by Tyler Murphy, co-founder of EasyOptOuts. In tests with voluntary participants, all generated addresses led to the “hidden” ones. Murphy had reported the vulnerability to Apple in June 2025. The company stated it had reviewed the case and resolved the issue. Further tests, however, showed that the gap still existed. About a year after the initial report, Murphy turned to “404 Media.”

More on the topic

Apple Closes Security Gap in iCloud+

In the original report, Murphy initially did not describe any technical details–a common practice for still-open vulnerabilities. This prevented others from mimicking the attack and accessing real email addresses. Now, Apple has confirmed to “404 Media” that the issue was “completely resolved” with an update on July 3.

Following the announcement, Murphy and EasyOptOut co-founder Ben Weiner disclosed how they were able to bypass Apple’s “Hide My Email” protection. The problem occurred when an incoming email was rejected as spam. In the email log–the exact activity record of an email–the sender could then see the hidden address.

Also of interest: Apple is working on an anti-theft feature for iPhones

Older Email Addresses Still Unsecure

The experts at EasyOptOut assume that there is still a risk for iCloud+ users. This is because email logs are often still accessible afterward. All private email addresses for which “Hide My Email” was used before the security update was released are likely still unprotected.

Users cannot easily find out if they are affected. This is because emails identified as spam are generally not forwarded from the anonymous address to the actual address.

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.