# Apple 'Hide My Email' Aliases Deanonymizable to Real Email Addresses (Unpatched 1+ Year)

> Apple's Hide My Email relay feature (iCloud+) contains an unpatched flaw that lets an attacker with limited technical skill reverse an anonymized alias back to the user's real underlying email address. Researcher Tyler Murphy (EasyOptOuts) reported it to Apple in June 2025 with reproduction steps; as of the July 1, 2026 public disclosure via 404 Media, Apple had not shipped a fix despite claiming in March 2026 that it had been 'addressed in a recent system change.'

- **Published:** 2026-07-01T00:00:00Z
- **Last reviewed:** 2026-07-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1043
- **ID:** TL-2026-1043
- **Severity:** MEDIUM
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Apple's Hide My Email, part of the iCloud+ subscription bundle, generates random word-plus-number email aliases under the @icloud.com domain (migrating to @private.icloud.com in a planned future change) that forward mail to a user's real address while concealing that address from the site or app the alias was given to. Researcher Tyler Murphy, co-founder of the opt-out service EasyOptOuts, discovered that these aliases can be reversed to recover the underlying real email address with 'limited technical skill.' In limited testing with volunteers, Murphy reported that 100% of Hide My Email addresses tested were exploitable: a newly generated alias was handed to Murphy, who was able to reply with the real email address tied to the Apple account it was supposed to hide.

Murphy reported the issue to Apple in June 2025 with detailed reproduction instructions. Apple acknowledged and began investigating in July 2025. In March 2026, Apple told Murphy the issue had been 'addressed in a recent system change'; Murphy re-tested and found the flaw still fully exploitable. Apple then requested additional information (April 2026) and said it was 'still investigating' (May 2026), asking Murphy not to disclose the issue publicly. In late May 2026 Apple promised a fix 'in the coming weeks.' No fix shipped, and Murphy coordinated disclosure with 404 Media, which independently validated the flaw and published on July 1, 2026, withholding the exact technical reproduction method because the bug remained exploitable at publication time.

Neither 404 Media nor Cyber Security News nor follow-on coverage (AppleInsider, TechCrunch) discloses the precise technical mechanism (e.g., whether it is a metadata leak, a predictable/derivable alias-to-account mapping, an API response disclosure, or a side channel in the mail-forwarding path); this is a deliberate responsible-disclosure omission while the bug remains live. No CVE identifier or CVSS score has been assigned as of this writing. The vulnerability does not itself involve code execution, malware, or data exfiltration in the traditional sense; its impact is deanonymization/identity-correlation, which downstream enables targeted phishing, doxxing, harassment, and account-linkage attacks against users who relied on Hide My Email to compartmentalize their identity (e.g., journalists, activists, domestic-abuse survivors, or privacy-conscious consumers signing up for services with an alias). A separate, related Apple change — migrating newly generated Hide My Email addresses from the shared @icloud.com domain to a dedicated @private.icloud.com domain — is scheduled for the coming weeks and has been criticized by Murphy and press coverage because it will let websites trivially identify and block Hide My Email addresses by domain, further eroding the feature's anonymity value (a related but distinct privacy regression, not the deanonymization bug itself).

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1589.002 Email Addresses
- T1593 Search Open Websites/Domains
- T1596 Search Open Technical Databases
- T1596.005 Scan Databases
- T1597 Search Closed Sources
- T1597.002 Purchase Technical Data
- T1598 Phishing for Information
- T1585 Establish Accounts
- T1585.002 Email Accounts
- T1586 Compromise Accounts
- T1566 Phishing
- T1566.002 Spearphishing Link
- T1213 Data from Information Repositories
- T1119 Automated Collection

## Sources

- [Apple 'Hide My Email' Vulnerability Enables Discovery of Real Email Addresses](https://cybersecuritynews.com/apple-hide-my-email-vulnerability/)
- [Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses](https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/)
- [Apple hasn't fixed a Hide My Email privacy bug in over a year](https://appleinsider.com/articles/26/07/01/apple-hasnt-fixed-a-hide-my-email-privacy-bug-in-over-a-year)
- [Apple plans to change its Hide My Email privacy feature that could make it less effective](https://techcrunch.com/2026/06/16/apple-plans-to-change-its-hide-my-email-privacy-feature-that-could-make-it-less-effective/)
- [Apple will hide your email address from apps and websites, but not cops](https://techcrunch.com/2026/03/30/apple-will-hide-your-email-address-from-apps-and-websites-but-not-cops/)
- [Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses (community discussion)](https://discuss.privacyguides.net/t/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/38930)
- [Apple is bringing Hide My Email and Sign in with Apple under one domain](https://www.helpnetsecurity.com/2026/06/17/apple-hide-my-email-domain-change/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1043
