# Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action Lawsuit (Alvarez v. Apple)

> Security researchers Tyler Murphy and Ben Weiner of EasyOptOuts found that Apple's iCloud+ Hide My Email relay leaked a user's real underlying email address inside bounce/non-delivery-report (NDR) mail logs whenever a message to the relay address was auto-rejected as spam. Reported to Apple on 2025-06-13, the flaw was falsely declared fixed in March 2026, remained exploitable through a second failed patch attempt on 2026-06-30, was publicly disclosed by 404 Media on 2026-07-01, and was finally patched on 2026-07-03 — prompting a proposed class action (Alvarez v. Apple, N.D. Cal., filed 2026-07-15) alleging false advertising, fraud, and breach of contract.

- **Published:** 2026-07-22T00:00:00Z
- **Last reviewed:** 2026-07-22T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1611
- **ID:** TL-2026-1611
- **Severity:** MEDIUM
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Apple's Hide My Email (part of iCloud+, launched with iOS 15/macOS Monterey in September 2021) generates a random-looking private relay alias (e.g. abc123@privaterelay.appleid.com) that forwards incoming mail to a subscriber's real address while, in theory, concealing that real address from the sender and from any service the alias was given to.

Security researchers Tyler Murphy and Ben Weiner (co-founders of EasyOptOuts, a data-broker opt-out service) discovered that this concealment broke down whenever a message sent to a Hide My Email alias was automatically rejected as spam by the recipient's mail infrastructure. In that case, the bounce / non-delivery report (NDR) generated by the sending mail server and logged in its own mail-transfer logs contained the subscriber's real, underlying email address — even when the triggering message was entirely legitimate (not spam at all, simply mis-classified by aggressive filters). No fetched source identified the specific SMTP/NDR header or field (e.g. Diagnostic-Code, envelope-from) responsible; reporting describes the mechanism generically as a mail-transfer-agent bounce-log leak reproducible across "major email hosts," without naming a specific provider. Murphy and Weiner stated that "100%" of aliases they examined were exploitable this way, and that almost anyone — with no elevated privileges, no insider access, and no purchased exploit — could send a single message to a target's Hide My Email alias and, if it happened to bounce, recover the real address from the resulting log entry. 404 Media reporter Joseph Cox independently reproduced the leak in roughly five minutes during his own testing. Because affected users rarely check their spam folders or the sender-side bounce logs, victims had no reliable way to know whether their real address had already leaked.

Murphy reported the issue to Apple on 2025-06-13; Apple acknowledged the report in July 2025. In March 2026, Apple told the researchers a system change had resolved the issue — but Murphy's continued testing showed the leak still occurred. In late May 2026 Apple said it would ship a fix in "a coming weeks" security update; Murphy and Cox independently retested around 2026-06-29/30 and found a second attempted fix still did not fully close the hole. 404 Media published the unpatched flaw on 2026-07-01, after which Apple told 404 Media the issue was "fully fixed" in a patch shipped 2026-07-03. Because mail-transfer logs at third-party mail providers are frequently retained for extended periods, the researchers warned that any Hide My Email alias created before 2026-07-07 may have already had its real address exposed and logged by a third party, independent of Apple's own fix.

No CVE identifier has been assigned. There is no public proof-of-concept exploit code, no reported case of in-the-wild abuse leading to spam/phishing/stalking, and no network infrastructure or malware associated with this disclosure — the vulnerability is a privacy/information-disclosure design flaw in a mail-relay feature, not an intrusion or malware campaign. The story's second axis is litigation: California (San Diego) resident Anthony Alvarez, who subscribed to a 200GB iCloud+ plan around 2025-03-15, filed a proposed class action (Alvarez v. Apple Inc., N.D. Cal., case gov.uscourts.cand.474371; filing date reported as 2026-07-15 by AppleInsider/9to5mac/The Cyber Express and as 2026-07-19 by Security Boulevard) on behalf of four proposed classes: a nationwide class of device purchasers who used Hide My Email, a California subclass of the same, a nationwide class of iCloud+ subscribers who used the feature, and a California subclass of the same. The complaint pleads causes of action under the California Unfair Competition Law, the California False Advertising Law, and the Consumers Legal Remedies Act, plus common-law fraud, negligent misrepresentation, breach of contract, breach of implied warranty, and unjust enrichment, alleging Apple's marketing of Hide My Email as privacy-preserving was false/misleading given the known-but-undisclosed year-long flaw. It seeks subscription reimbursement, damages (aggregate class-wide controversy alleged at over $5,000,000), and injunctive relief compelling Apple to fix the feature or clearly disclose its limitations. No named law firm, attorney, or presiding judge for the case was disclosed in any fetched reporting. Commentary from AppleInsider (bylined Marcus Mendes) characterized the suit as opportunistic ("ambulance chasing"), noting Alvarez does not allege his own address was ever exposed or misused, and that no confirmed real-world attack using the flaw has been documented. The story was additionally covered by Cult of Mac, MacObserver, iDropNews, MacTrast, MacDailyNews, and TidBITS.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1589.002 Email Addresses
- T1596 Search Open Technical Databases
- T1585.002 Email Accounts
- T1114 Email Collection
- T1114.002 Remote Email Collection
- T1213 Data from Information Repositories
- T1598 Phishing for Information
- T1593 Search Open Websites/Domains
- T1589.001 Credentials
- T1591 Gather Victim Org Information
- T1594 Search Victim-Owned Websites
- T1598.001 Spearphishing Service
- T1598.003 Spearphishing Link
- T1585 Establish Accounts
- T1586.002 Email Accounts
- T1566 Phishing
- T1566.002 Spearphishing Link
- T1560 Archive Collected Data
- T1087 Account Discovery

## Sources

- [Apple Hide My Email Lawsuit](https://thecyberexpress.com/apple-hide-my-email-lawsuit/)
- [Apple Patches Hide My Email Flaw More Than a Year After It Was Reported](https://www.macrumors.com/2026/07/21/apple-patches-hide-my-email-flaw/)
- [Apple Faces Class-Action Lawsuit Over Alleged Hide My Email Security Flaw](https://securityboulevard.com/2026/07/apple-faces-class-action-lawsuit-over-alleged-hide-my-email-security-flaw/)
- [Class action accuses Apple of misleading users about Hide My Email's privacy protections](https://9to5mac.com/2026/07/16/class-action-accuses-apple-of-misleading-users-about-hide-my-emails-privacy-protections/)
- [Hide My Email class action lawsuit seeks payout without evidence of any attacks](https://appleinsider.com/articles/26/07/16/hide-my-email-class-action-lawsuit-seeks-payout-without-evidence-of-any-attacks)
- [Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs](https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html)
- [Apple Fixes Hide My Email Vulnerability After 404 Media Coverage](https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/)
- [Alvarez v. Apple Inc. — Class Action Complaint (N.D. Cal., gov.uscourts.cand.474371)](https://storage.courtlistener.com/recap/gov.uscourts.cand.474371/gov.uscourts.cand.474371.1.0.pdf)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1611
