Threat reportVulnerabilityTL-2026-1043
Apple 'Hide My Email' Aliases Deanonymizable to Real Email Addresses (Unpatched 1+ Year)
Apple 'Hide My Email' Aliases Deanonymizable to Real Email (TL-2026-1043), also tracked as Hide My Email Deanonymization Bug, is a medium-severity software vulnerability, first published 2026-07-01. It has no confirmed attribution, affects Apple Hide My Email (iCloud+), maps to 15 MITRE ATT&CK techniques (T1119, T1213, T1566), and is covered by 9 detection rules and 19 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-1043
- Threat ID
- TL-2026-1043
- Also known as
- Hide My Email Deanonymization Bug, iCloud+ Email Relay Identity Leak
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- consumer, technology, news - media, civil society, government administration
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 19
How Apple 'Hide My Email' Aliases Deanonymizable to Real Email works
Apple's Hide My Email relay feature (iCloud+) contains an unpatched flaw that lets an attacker with limited technical skill reverse an anonymized alias back to the user's real underlying email address. Researcher Tyler Murphy (EasyOptOuts) reported it to Apple in June 2025 with reproduction steps; as of the July 1, 2026 public disclosure via 404 Media, Apple had not shipped a fix despite claiming in March 2026 that it had been 'addressed in a recent system change.'
Apple's Hide My Email, part of the iCloud+ subscription bundle, generates random word-plus-number email aliases under the @icloud.com domain (migrating to @private.icloud.com in a planned future change) that forward mail to a user's real address while concealing that address from the site or app the alias was given to. Researcher Tyler Murphy, co-founder of the opt-out service EasyOptOuts, discovered that these aliases can be reversed to recover the underlying real email address with 'limited technical skill.' In limited testing with volunteers, Murphy reported that 100% of Hide My Email addresses tested were exploitable: a newly generated alias was handed to Murphy, who was able to reply with the real email address tied to the Apple account it was supposed to hide.
Murphy reported the issue to Apple in June 2025 with detailed reproduction instructions. Apple acknowledged and began investigating in July 2025. In March 2026, Apple told Murphy the issue had been 'addressed in a recent system change'; Murphy re-tested and found the flaw still fully exploitable. Apple then requested additional information (April 2026) and said it was 'still investigating' (May 2026), asking Murphy not to disclose the issue publicly. In late May 2026 Apple promised a fix 'in the coming weeks.' No fix shipped, and Murphy coordinated disclosure with 404 Media, which independently validated the flaw and published on July 1, 2026, withholding the exact technical reproduction method because the bug remained exploitable at publication time.
Neither 404 Media nor Cyber Security News nor follow-on coverage (AppleInsider, TechCrunch) discloses the precise technical mechanism (e.g., whether it is a metadata leak, a predictable/derivable alias-to-account mapping, an API response disclosure, or a side channel in the mail-forwarding path); this is a deliberate responsible-disclosure omission while the bug remains live. No CVE identifier or CVSS score has been assigned as of this writing. The vulnerability does not itself involve code execution, malware, or data exfiltration in the traditional sense; its impact is deanonymization/identity-correlation, which downstream enables targeted phishing, doxxing, harassment, and account-linkage attacks against users who relied on Hide My Email to compartmentalize their identity (e.g., journalists, activists, domestic-abuse survivors, or privacy-conscious consumers signing up for services with an alias). A separate, related Apple change — migrating newly generated Hide My Email addresses from the shared @icloud.com domain to a dedicated @private.icloud.com domain — is scheduled for the coming weeks and has been criticized by Murphy and press coverage because it will let websites trivially identify and block Hide My Email addresses by domain, further eroding the feature's anonymity value (a related but distinct privacy regression, not the deanonymization bug itself).
MITRE ATT&CK techniques used in TL-2026-1043
Collection
T1119 Automated Collection; T1213 Data from Information Repositories
Initial Access
T1566 Phishing; T1566.002 Spearphishing Link
Resource Development
T1585 Establish Accounts; T1585.002 Email Accounts; T1586 Compromise Accounts
Reconnaissance
T1589 Gather Victim Identity Information; T1589.002 Email Addresses; T1593 Search Open Websites/Domains; T1596 Search Open Technical Databases; T1596.005 Scan Databases; T1597 Search Closed Sources; T1597.002 Purchase Technical Data; T1598 Phishing for Information
Affected products and versions in Apple 'Hide My Email' Aliases Deanonymizable to Real Email
- Apple — Hide My Email (iCloud+)
Vulnerable versions: all Hide My Email aliases as of 2026-07-01
Remediation for Apple 'Hide My Email' Aliases Deanonymizable to Real Email
Patches
- No vendor patch has been publicly confirmed or verified as of 2026-07-01; Apple claimed a fix in March 2026 that testing showed was ineffective, and promised another fix 'in the coming weeks' as of late May 2026
Immediate actions
- Treat existing Hide My Email aliases as potentially linkable to your real email address until Apple confirms a fix
- High-risk users (journalists, activists, domestic-abuse survivors, executives) should avoid relying on Hide My Email as a sole anonymity control for sensitive signups
- Monitor accounts tied to Hide My Email aliases for unusual phishing or credential-stuffing attempts, since a leaked real address can be used for targeted follow-on attacks
- Where possible, pair Hide My Email aliases with a secondary, unrelated real mailbox not otherwise exposed, to reduce blast radius if the alias is deanonymized
Workarounds
- Assume any existing Hide My Email alias may be reversible to the real address and avoid using it for accounts where identity exposure carries high risk
- Use alternate/third-party email alias or forwarding services with a demonstrated non-reversible design for sensitive signups
Longer-term hardening
- Apple should ship and confirm a verified fix to the alias-to-identity reversal flaw, not just an internal 'system change' claim
- Independent re-validation of any Apple-issued fix by the original reporter (EasyOptOuts) or a third party before considering the issue resolved
- Apple should reconsider the @private.icloud.com domain migration, which trades deanonymization risk for trivial alias-blocking by third-party sites
- Users should diversify email-alias providers (e.g., SimpleLogin, Firefox Relay, AnonAddy) rather than depending on a single vendor's alias implementation
Weaknesses (CWE) in Apple 'Hide My Email' Aliases Deanonymizable to Real Email
Timeline of Apple 'Hide My Email' Aliases Deanonymizable to Real Email
- Tyler Murphy (EasyOptOuts co-founder) discovers the Hide My Email deanonymization flaw and reports it to Apple with detailed reproduction instructions.
- Apple acknowledges the report and states it is investigating the issue.
- Apple tells Murphy the issue has been 'addressed in a recent system change'; Murphy re-tests and confirms the vulnerability is still fully exploitable.
- Apple requests additional information from Murphy and states it is performing further checks.
- Apple tells Murphy it is 'still investigating' the issue and asks him not to disclose it publicly; Murphy proposes Apple halt Hide My Email sales until a fix ships.
- Apple promises a security update addressing the issue is 'expected in the coming weeks.'
- Apple issues a domain-consolidation notice stating that newly generated Hide My Email addresses and Sign in with Apple relay addresses (currently under privaterelay.appleid.com) will both migrate to the shared private.icloud.com domain; existing addresses on legacy domains continue to work.
- TechCrunch and Help Net Security report on the planned @private.icloud.com domain consolidation, noting it removes source ambiguity and could let third-party sites trivially identify and block Hide My Email/Sign in with Apple relay addresses.
- 404 Media confirms the deanonymization exploit remains fully active and unpatched as of this date, immediately prior to publication.
- 404 Media (journalist Joseph Cox) publishes the vulnerability with Murphy's account, withholding exact technical details because the flaw remains exploitable; Cyber Security News, AppleInsider, and other outlets pick up coverage the same day. No fix has shipped and no CVE has been assigned.
Sources cited for Apple 'Hide My Email' Aliases Deanonymizable to Real Email
- Apple 'Hide My Email' Vulnerability Enables Discovery of Real Email Addresses
- Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses
- Apple hasn't fixed a Hide My Email privacy bug in over a year
- Apple plans to change its Hide My Email privacy feature that could make it less effective
- Apple will hide your email address from apps and websites, but not cops
- Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses (community discussion)
- Apple is bringing Hide My Email and Sign in with Apple under one domain
Detection coverage for TL-2026-1043
As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1043 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.