Apple patched a privacy vulnerability in Hide My Email that exposed users' real email addresses in Mail application logs. The flaw allowed real addresses to be unmasked despite the service's core purpose of masking email identity.
Security researcher Tyler Murphy, co-founder of EasyOptOuts, discovered the vulnerability and disclosed it to Apple over a year before the company deployed a fix on July 3, 2026. The bug undermined Hide My Email's fundamental privacy guarantee by logging actual email addresses in plain text within the Mail app's local logs.
Hide My Email operates as part of Apple's Sign in with Apple ecosystem, generating masked email addresses that forward messages to users' real inboxes while keeping their actual email hidden from services and websites. The vulnerability negated this protection by storing real addresses in application logs accessible on affected devices.
The extended timeline between disclosure and remediation raises questions about Apple's vulnerability response process. A year-plus remediation window leaves users unknowingly exposed to local data extraction risks. Attackers with device access or those exploiting separate vulnerabilities to gain log file access could harvest real email addresses from affected systems.
The fix prevents Hide My Email addresses from exposing real addresses in Mail logs, restoring the service's intended privacy model. Apple has not disclosed the exact number of users impacted or provided guidance on whether previously exposed logs require manual deletion.
Users relying on Hide My Email for privacy should verify their Mail app logs have been cleaned following the update. Organizations managing iOS fleets should confirm patch deployment across their environments. The incident underscores how privacy-focused features require careful implementation across all system components. A single logging mechanism can compromise an entire privacy architecture if not properly secured.
