Apple Hide My Email May Not Protect Your Address

Hide My Email was created so people would not have to give their real email address to every app or website that asks for one. A recent report from 404 Media says a vulnerability in Hide My Email can allow someone to discover the real address behind an Apple-generated alias. According to the report, Apple has been aware of the problem for more than a year.

Security researcher Tyler Murphy discovered the issue and reported it to Apple in June 2025. Apple acknowledged the report in July. Murphy tested the vulnerability using volunteers who allowed him to run the test on their accounts, and every test he ran proved exploitable. 404 Media performed its own verification by testing one of its addresses and reached the same conclusion.

No one has published a step-by-step explanation of the vulnerability, because releasing the technical details would effectively hand out an exploit that others could use. Murphy told 404 Media that people-search services are already capable of linking email addresses to a person’s name and location. Recovering the underlying real address from an Apple alias can be enough on its own to identify and profile someone.

What Apple Has Said So Far

Apple stated in March that it had fixed the problem, but that fix did not fully resolve the issue. Over the following months the company issued further statements in April and May, including promises that a security patch would arrive within weeks. As of the latest reports, that promised patch had not yet been released.

This vulnerability is not only an Apple problem in principle. Google has been developing a similar privacy feature for Gmail, reportedly called Shielded Email, which appeared in teardown reports in 2024. That feature has not launched, and therefore has not been broadly tested in the wild. The history of privacy tools shows that they can appear to work correctly until researchers or attackers actively probe them, which is when flaws commonly surface.

Because of the ongoing uncertainty and the delay in an official, confirmed fix, anyone relying on Hide My Email to shield their true address should assume the alias may not be fully private. Until Apple delivers a verified patch and provides clear guidance about the fix, users who need strong privacy guarantees should consider additional measures, such as using separate accounts, paid anonymous email forwarding services, or temporary addresses from well-vetted providers.

For people concerned about identity exposure, the practical takeaway is straightforward: treat Hide My Email as a convenience feature, not as a guaranteed layer of anonymity. Even when a feature is designed with privacy in mind, implementation flaws can undermine protections. Staying cautious, monitoring accounts for suspicious activity, and adopting layered privacy practices remain important while companies address reported vulnerabilities.

Apple’s public communications and timelines around the reported vulnerability have drawn scrutiny because of the gap between promises and the absence of a visible patch. Security researchers and privacy advocates typically want transparent, timely updates and clear verification that vulnerabilities have been fixed. In this case, observers note that an acknowledged bug combined with repeated delay reduces user confidence in the feature’s current safety.

Finally, anyone using alias services should be mindful that indirect information can reveal real identities. Third-party data brokers and people-search sites often combine public records, leaked databases, and other signals to connect contact information with personal details. If an alias can be linked back to a real email, that connection can be enough to deanonymize its owner.

Until Apple confirms a complete resolution and publishes guidance demonstrating the issue is closed, assume Hide My Email may not fully protect your actual address and act accordingly.