Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action Lawsuit (Alvarez v. Apple) — Threadlinqs Intelligence
As of 2026-07-22, Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action Lawsuit (Alvarez v. Apple) is a medium-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1611 · Severity: MEDIUM · Status: PATCHED · Category: VULNERABILITY
Security researchers Tyler Murphy and Ben Weiner of EasyOptOuts found that Apple's iCloud+ Hide My Email relay leaked a user's real underlying email address inside bounce/non-delivery-report (NDR)
Apple's Hide My Email (part of iCloud+, launched with iOS 15/macOS Monterey in September 2021) generates a random-looking private relay alias (e.g. abc123@privaterelay.appleid.com) that forwards incoming mail to a subscriber's real address while, in theory, concealing that real address from the sender and from any service the alias was given to.
Security researchers Tyler Murphy and Ben Weiner (co-founders of EasyOptOuts, a data-broker opt-out service) discovered that this concealment broke down whenever a message sent to a Hide My Email alias was automatically rejected as spam by the recipient's mail infrastructure. In that case, the bounce / non-delivery report (NDR) generated by the sending mail server and logged in its own mail-transfer logs contained the subscriber's real, underlying email address — even when the triggering message was entirely legitimate (not spam at all, simply mis-classified by aggressive filters). No fetched source identified the specific SMTP/NDR header or field (e.g. Diagnostic-Code, envelope-from) responsible; reporting describes the mechanism generically as a mail-transfer-agent bounce-log leak reproducible across "major email hosts," without naming a specific provider. Murphy and Weiner stated that "100%" of aliases they examined were exploitable this way, and that almost anyone — with no elevated privileges, no insider access, and no purchased exploit — could send a single message to a target's Hide My Email alias and, if it happened to bounce, recover the real address from the resulting log entry. 404 Media reporter Joseph Cox independently reproduced the leak in roughly five minutes during his own testing. Because affected users rarely check their spam folders or the sender-side bounce logs, victims had no reliable way to know whether their real address had already leaked.
Murphy reported the issue to Apple on 2025-06-13; Apple acknowledged the report in July 2025. In March 2026, Apple told the researchers a system change had resolved the issue — but Murphy's continued testing showed the leak still occurred. In late May 2026 Apple said it would ship a fix in "a coming weeks" security update; Murphy and Cox independently retested around 2026-06-29/30 and found a second attempted fix still did not fully close the hole. 404 Media published the unpatched flaw on 2026-07-01, after which Apple told 404 Media the issue was "fully fixed" in a patch shipped 2026-07-03. Because mail-transfer logs at third-party mail providers are frequently retained for extended periods, the researchers warned that any Hide My Email alias created before 2026-07-07 may have already had its real address exposed and logged by a third party, independent of Apple's own fix.
No CVE identifier has been assigned. There is no public proof-of-concept exploit code, no reported case of in-the-wild abuse leading to spam/phishing/stalking, and no network infrastructure or malware associated with this disclosure — the vulnerability is a privacy/information-disclosure design flaw in a mail-relay feature, not an intrusion or malware campaign. The story's second axis is litigation: California (San Diego) resident Anthony Alvarez, who subscribed to a 200GB iCloud+ plan around 2025-03-15, filed a proposed class action (Alvarez v. Apple Inc., N.D. Cal., case gov.uscourts.cand.474371; filing date reported as 2026-07-15 by AppleInsider/9to5mac/The Cyber Express and as 2026-07-19 by Security Boulevard) on behalf of four proposed classes: a nationwide class of device purchasers who used Hide My Email, a California subclass of the same, a nationwide class of iCloud+ subscribers who used the feature, and a California subclass of the same. The complaint pleads causes of action under the California Unfair Competition Law, the California False Advertising Law, and the Consumers Legal Remedies Act, plus common-law fraud, negligent misrepresentation, breach of contract, breach of implied warranty, and unjust enrichment, alleging Apple's marketing o
Weaknesses (CWE)
CWE-200, CWE-209
Target sectors: consumer technology, email communications services, personal privacy
Target regions: united states of america, Global
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, MEDIUM, threat intelligence, cybersecurity, T1589, T1589.002, T1596, T1585.002, T1114, T1114.002, T1213, T1598, T1593, T1589.001