A researcher says a vulnerability in Apple's Hide My Email tool lets anyone see a user's real email address; first reported in June 2025, Apple has not fixed it
“Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses,” the person who reported the issue said.
Context & Ripple Effects
Apple’s email-privacy features have appeared in related coverage alongside several earlier cases in which Mail, macOS, or network-privacy behavior exposed information users expected to be protected. The current report matters because it concerns an identity-masking layer rather than merely the handling of message content.
The related record also includes a later fix for a Private Wi-Fi Address exposure, showing that Apple has addressed comparable privacy gaps in other product areas. Here, however, the reported issue has remained unresolved since its disclosure, making the duration of exposure part of the story.
First-order effects
- People using Hide My Email may no longer be able to assume that an alias prevents a recipient or attacker from associating activity with their underlying inbox.
- Apple faces an immediate trust and remediation issue around a privacy feature whose value depends on keeping the destination address undiscoverable.
Second-order effects
- Services and users that rely on aliases to limit unwanted contact may need to treat those aliases as less effective until the issue is resolved, increasing the value of account-specific monitoring and address rotation where available.
- Competing privacy and email-alias products gain a clearer point of comparison: not just whether they mask addresses, but how they handle disclosure reports and prevent alias-to-inbox correlation.
Third-order effects
- If repeated privacy-feature exposures and delayed fixes persist, consumers may evaluate platform privacy claims more on implementation reliability and response speed than on feature availability alone.
- The pattern points toward greater scrutiny of identity-masking tools as security boundaries: a feature marketed as privacy-enhancing must be assessed for whether metadata or implementation details can undo that protection.
The trend: Privacy features are increasingly judged as operational security services, where the durability of the protection and the vendor’s remediation process matter as much as the feature’s stated design.