July 22, 2026, 1:45 pm | Read time: 3 minutes
With an iCloud+ subscription, Apple users receive several benefits over the basic offering. One of these is the “Hide My Email” feature. This allows users to sign up for apps and websites with randomly generated email addresses. It is intended to maintain user anonymity–but it hasn’t always worked reliably. A flaw led to private email addresses being visible. Now, Apple has closed this security gap.
Hidden Addresses Freely Visible
“Hide My Email” is integrated into “Sign in with Apple” and gives users the option to create an anonymous email address when signing up. Where login with Apple isn’t possible, users can simply generate an address along with a secure password and save it in the Passwords app. The generated addresses usually consist of two random words, a number, and the suffix “@icloud.com.” Emails are forwarded to the real address and appear as usual in the inbox.
However, as “404 Media” reported in early July, the real address could still be discovered. This was found by Tyler Murphy, co-founder of EasyOptOuts. In tests with voluntary participants, all generated addresses led to the “hidden” ones. Murphy had reported the vulnerability to Apple in June 2025. The company stated it had reviewed the case and resolved the issue. Further tests, however, showed that the gap still existed. About a year after the initial report, Murphy turned to “404 Media.”
Apple Users Should Avoid This Feature for Now
iCloud Users Beware: Storage Full?
Apple Closes Security Gap in iCloud+
In the original report, Murphy initially did not describe any technical details–a common practice for still-open vulnerabilities. This prevented others from mimicking the attack and accessing real email addresses. Now, Apple has confirmed to “404 Media” that the issue was “completely resolved” with an update on July 3.
Following the announcement, Murphy and EasyOptOut co-founder Ben Weiner disclosed how they were able to bypass Apple’s “Hide My Email” protection. The problem occurred when an incoming email was rejected as spam. In the email log–the exact activity record of an email–the sender could then see the hidden address.
Also of interest: Apple is working on an anti-theft feature for iPhones
Older Email Addresses Still Unsecure
The experts at EasyOptOut assume that there is still a risk for iCloud+ users. This is because email logs are often still accessible afterward. All private email addresses for which “Hide My Email” was used before the security update was released are likely still unprotected.
Users cannot easily find out if they are affected. This is because emails identified as spam are generally not forwarded from the anonymous address to the actual address.