A vulnerability in Apple's privacy-focused 'Hide My Email' service has been found to leak users' actual email addresses. The flaw undermines the core purpose of the feature, which generates masked addresses to protect user identity.
Apple's 'Hide My Email' feature, part of iCloud+, was designed to let users create masked email addresses that forward to their real inboxes while keeping their primary address hidden. Security researchers discovered that the implementation contains a vulnerability allowing attackers to reveal the underlying email addresses.
The vulnerability works by exploiting how Apple handles the forwarding mechanism. By analyzing server responses and metadata, attackers can determine which real email address corresponds to a masked address, effectively defeating the privacy protection.
The issue highlights a common challenge in privacy-focused tools: the gap between design intent and actual implementation. Users who believed their real addresses were protected could be exposed to targeted attacks, spam, or social engineering.
Apple has not yet publicly acknowledged the vulnerability or announced a fix. The feature remains active across iPhone, iPad, Mac, and web platforms. Users currently relying on 'Hide My Email' for privacy may want to reconsider how they're using masked addresses until Apple addresses the issue.
This discovery adds to ongoing scrutiny of Apple's privacy claims. The company has marketed itself as privacy-first, yet security researchers continue to uncover gaps between marketing and reality.
For users who have already created masked addresses through the service, the immediate risk depends on whether any attacker has already exploited this vulnerability. Those who shared masked addresses with untrusted services face the highest exposure.
The vulnerability was reported to Apple ahead of public disclosure, following standard security research practice. The timeline for a fix remains unclear.
Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.
A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.
McKesson, a major healthcare and pharmaceutical distributor, confirmed a cybersecurity incident involving unauthorized access to third-party applications. Extortion group ShinyHunters claims responsibility for stealing 284 million patient data records.
Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.