Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple’s latest software update has patched a vulnerability that exposed users’ real email addresses when they used the company’s “Hide My Email” feature. This flaw allowed hackers to reveal sensitive information by exploiting a weakness in Apple’s email masking system, putting millions of users at risk.

The issue was discovered in Apple’s Mail app, which uses a service called “Hide My Email” to generate temporary, disposable email addresses for signing up to services or registering online accounts. The feature is designed to keep users’ real email addresses hidden from unwanted solicitations and spam. However, researchers found that by analyzing the email logs generated by the Hide My Email system, it was possible to identify the user’s actual email address.

The vulnerability worked because Apple’s Mail app stores a unique identifier for each temporary email address in its log files. By analyzing these logs, hackers could match the temporary addresses with their corresponding real email addresses. This allowed them to gather sensitive information about users, including their online activity and potentially even their personal details.

Apple has taken steps to fix this issue by updating its Mail app to remove the unique identifiers from the email logs. However, the discovery highlights the potential risks of relying on software systems that use AI-powered features, such as Apple’s Hide My Email service. These systems can be vulnerable to attacks if not properly secured, and users may not even be aware they are at risk.

The exposure of sensitive information through this vulnerability is particularly concerning because it can have long-lasting consequences for users’ online security. Once hackers obtain a user’s real email address, they can use it to launch targeted phishing attacks or even sell the information on the dark web. Users who have used Apple’s Hide My Email feature in the past may want to take steps to secure their accounts and monitor their online activity closely.

To mitigate this risk, users should be cautious when using any software system that relies on AI-powered features. They should regularly review their account settings and log files for any suspicious activity, and consider enabling two-factor authentication whenever possible. By taking proactive steps to protect themselves, users can minimize the impact of vulnerabilities like this one and stay safer online.


Source: The Hacker News — 2026-07-21