Threat reportVulnerabilityTL-2026-1611

Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action Lawsuit (Alvarez v. Apple)

mediumPATCHED

Apple Hide My Email Address-Disclosure Flaw (TL-2026-1611), also tracked as Hide My Email address-disclosure flaw, is a medium-severity software vulnerability, first published 2026-07-22. It has no confirmed attribution, affects Apple iCloud+ Hide My Email, maps to 20 MITRE ATT&CK techniques (T1087, T1114, T1114.002), and is covered by 9 detection rules and 26 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-1611

Threat ID
TL-2026-1611
Also known as
Hide My Email address-disclosure flaw, iCloud+ relay bounce leak
Severity
MEDIUM
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
consumer technology, email communications services, personal privacy
Target regions
united states of america, Global
Detection rules
9
Indicators of compromise
26

How Apple Hide My Email Address-Disclosure Flaw works

Security researchers Tyler Murphy and Ben Weiner of EasyOptOuts found that Apple's iCloud+ Hide My Email relay leaked a user's real underlying email address inside bounce/non-delivery-report (NDR) mail logs whenever a message to the relay address was auto-rejected as spam. Reported to Apple on 2025-06-13, the flaw was falsely declared fixed in March 2026, remained exploitable through a second failed patch attempt on 2026-06-30, was publicly disclosed by 404 Media on 2026-07-01, and was finally patched on 2026-07-03 — prompting a proposed class action (Alvarez v. Apple, N.D. Cal., filed 2026-07-15) alleging false advertising, fraud, and breach of contract.

Apple's Hide My Email (part of iCloud+, launched with iOS 15/macOS Monterey in September 2021) generates a random-looking private relay alias (e.g. abc123@privaterelay.appleid.com) that forwards incoming mail to a subscriber's real address while, in theory, concealing that real address from the sender and from any service the alias was given to.

Security researchers Tyler Murphy and Ben Weiner (co-founders of EasyOptOuts, a data-broker opt-out service) discovered that this concealment broke down whenever a message sent to a Hide My Email alias was automatically rejected as spam by the recipient's mail infrastructure. In that case, the bounce / non-delivery report (NDR) generated by the sending mail server and logged in its own mail-transfer logs contained the subscriber's real, underlying email address — even when the triggering message was entirely legitimate (not spam at all, simply mis-classified by aggressive filters). No fetched source identified the specific SMTP/NDR header or field (e.g. Diagnostic-Code, envelope-from) responsible; reporting describes the mechanism generically as a mail-transfer-agent bounce-log leak reproducible across "major email hosts," without naming a specific provider. Murphy and Weiner stated that "100%" of aliases they examined were exploitable this way, and that almost anyone — with no elevated privileges, no insider access, and no purchased exploit — could send a single message to a target's Hide My Email alias and, if it happened to bounce, recover the real address from the resulting log entry. 404 Media reporter Joseph Cox independently reproduced the leak in roughly five minutes during his own testing. Because affected users rarely check their spam folders or the sender-side bounce logs, victims had no reliable way to know whether their real address had already leaked.

Murphy reported the issue to Apple on 2025-06-13; Apple acknowledged the report in July 2025. In March 2026, Apple told the researchers a system change had resolved the issue — but Murphy's continued testing showed the leak still occurred. In late May 2026 Apple said it would ship a fix in "a coming weeks" security update; Murphy and Cox independently retested around 2026-06-29/30 and found a second attempted fix still did not fully close the hole. 404 Media published the unpatched flaw on 2026-07-01, after which Apple told 404 Media the issue was "fully fixed" in a patch shipped 2026-07-03. Because mail-transfer logs at third-party mail providers are frequently retained for extended periods, the researchers warned that any Hide My Email alias created before 2026-07-07 may have already had its real address exposed and logged by a third party, independent of Apple's own fix.

No CVE identifier has been assigned. There is no public proof-of-concept exploit code, no reported case of in-the-wild abuse leading to spam/phishing/stalking, and no network infrastructure or malware associated with this disclosure — the vulnerability is a privacy/information-disclosure design flaw in a mail-relay feature, not an intrusion or malware campaign. The story's second axis is litigation: California (San Diego) resident Anthony Alvarez, who subscribed to a 200GB iCloud+ plan around 2025-03-15, filed a proposed class action (Alvarez v. Apple Inc., N.D. Cal., case gov.uscourts.cand.474371; filing date reported as 2026-07-15 by AppleInsider/9to5mac/The Cyber Express and as 2026-07-19 by Security Boulevard) on behalf of four proposed classes: a nationwide class of device purchasers who used Hide My Email, a California subclass of the same, a nationwide class of iCloud+ subscribers who used the feature, and a California subclass of the same. The complaint pleads causes of action under the California Unfair Competition Law, the California False Advertising Law, and the Consumers Legal Remedies Act, plus common-law fraud, negligent misrepresentation, breach of contract, breach of implied warranty, and unjust enrichment, alleging Apple's marketing of Hide My Email as privacy-preserving was false/misleading given the known-but-undisclosed year-long flaw. It seeks subscription reimbursement, damages (aggregate class-wide controversy alleged at over $5,000,000), and injunctive relief compelling Apple to fix the feature or clearly disclose its limitations. No named law firm, attorney, or presiding judge for the case was disclosed in any fetched reporting. Commentary from AppleInsider (bylined Marcus Mendes) characterized the suit as opportunistic ("ambulance chasing"), noting Alvarez does not allege his own address was ever exposed or misused, and that no confirmed real-world attack using the flaw has been documented. The story was additionally covered by Cult of Mac, MacObserver, iDropNews, MacTrast, MacDailyNews, and TidBITS.

MITRE ATT&CK techniques used in TL-2026-1611

Discovery

T1087 Account Discovery

Collection

T1114 Email Collection; T1114.002 Remote Email Collection; T1213 Data from Information Repositories; T1560 Archive Collected Data

Initial Access

T1566 Phishing; T1566.002 Spearphishing Link

Resource Development

T1585 Establish Accounts; T1585.002 Email Accounts; T1586.002 Email Accounts

Reconnaissance

T1589 Gather Victim Identity Information; T1589.001 Credentials; T1589.002 Email Addresses; T1591 Gather Victim Org Information; T1593 Search Open Websites/Domains; T1594 Search Victim-Owned Websites; T1596 Search Open Technical Databases; T1598 Phishing for Information; T1598.001 Spearphishing Service; T1598.003 Spearphishing Link

Affected products and versions in Apple Hide My Email Address-Disclosure Flaw

  • Apple — iCloud+ Hide My Email
    Vulnerable versions: Hide My Email service, all aliases created before 2026-07-07 (launched September 2021 with iOS 15 / macOS Monterey)
    Fixed in: Hide My Email backend fix deployed 2026-07-03 (server-side relay/NDR handling change, no client update required)
  • Apple — Sign in with Apple (private email relay)
    Vulnerable versions: Alleged in class-action complaint to share the underlying relay mechanism with Hide My Email
    Fixed in: Not separately confirmed by Apple or independent reporting; addressed only inferentially via the 2026-07-03 fix

Remediation for Apple Hide My Email Address-Disclosure Flaw

Patches

  • Apple deployed a fix for the Hide My Email bounce/NDR address-disclosure issue on 2026-07-03 (initial claimed-fixed system change in March 2026 did not fully resolve it; a second fix attempt on 2026-06-30 also proved incomplete)

Immediate actions

  • Treat any Hide My Email alias created before 2026-07-07 as potentially linked to your real address in third-party mail logs; consider rotating/deactivating and regenerating aliases for sensitive signups
  • Review spam/junk folders and any bounce-handling automation for messages sent to Hide My Email aliases prior to the July 2026 fix
  • Monitor real underlying email addresses tied to older Hide My Email aliases for unexpected spam, phishing, or data-broker contact as an indicator of prior exposure

Workarounds

  • Avoid using Hide My Email aliases for signups where the sender's spam-filtering behavior is unknown or aggressive, prior to confirming the July 2026 patch is in effect
  • Use a fully independent email alias/forwarding provider not tied to Apple ID for the most sensitive registrations until third-party log retention risk is assessed

Longer-term hardening

  • For privacy-relay/email-masking services, treat bounce/NDR generation as a sensitive data path requiring the same anti-leak scrutiny as the forwarding path itself
  • Independently verify vendor claims that a privacy/security fix has shipped rather than relying on vendor self-attestation, especially for consumer privacy features marketed as a paid benefit
  • Design relay/aliasing systems so that non-delivery reports are generated and returned using the alias identity only, never the underlying real recipient

Weaknesses (CWE) in Apple Hide My Email Address-Disclosure Flaw

CWE-200, CWE-209

Timeline of Apple Hide My Email Address-Disclosure Flaw

  • Security researcher Tyler Murphy (EasyOptOuts) discovers the Hide My Email bounce/NDR address-disclosure flaw and reports it to Apple.
  • Apple acknowledges receipt of the vulnerability report from Murphy.
  • Apple tells the researchers a system change has resolved the issue; Murphy's continued testing later shows the leak still occurs.
  • Apple tells the researchers it will ship a fix in a coming security update after being shown the issue was not actually resolved.
  • Murphy and 404 Media reporter Joseph Cox independently retest the flaw and confirm it is still exploitable ahead of publication.
  • A second Apple remediation attempt still fails to fully close the bounce/NDR leak, per researcher testing.
  • 404 Media publishes the first public report on the unpatched Hide My Email flaw, based on Murphy and Weiner's findings.
  • Apple deploys a server-side fix to the Hide My Email relay/bounce handling; Apple tells 404 Media the issue is now fully fixed.
  • Researchers note that any Hide My Email alias created before this date may already have had its real address exposed and retained in third-party mail-transfer logs, independent of the Apple-side fix.
  • Anthony Alvarez, a San Diego resident and 200GB iCloud+ subscriber since 2025-03-15, files a proposed class action, Alvarez v. Apple Inc., in the U.S. District Court for the Northern District of California (case gov.uscourts.cand.474371), on behalf of four proposed nationwide/California classes, alleging false advertising, fraud, and breach of contract related to the flaw. (Security Boulevard reports the filing date as 2026-07-19; other outlets report 2026-07-15/16.)
  • MacRumors, The Hacker News, and 404 Media publish fuller technical details of the bounce/NDR mechanism and the extended patch timeline following the patch's deployment.
  • The Cyber Express covers the lawsuit and disclosure timeline; threat entry created for tracking.

Sources cited for Apple Hide My Email Address-Disclosure Flaw

Detection coverage for TL-2026-1611

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1611 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats