SYLEN
AboutNewsConferenceMembershipDonate

Email updates

Conference, news, and membership updates by email.

Site

  • About
  • News
  • Membership
  • Waitlist
  • Donate

Conference

  • Conference 2027
  • Call for papers

Account

  • Create account
  • Membership details

SYLEN

  • Guidelines
  • Privacy
  • Terms

© 2026 Systems Leadership and Engineering Network. sylen.org.

Membership details →
Back to news
General SESource: easyoptouts.comJuly 1, 2026

Apple Hide My Email Vulnerability Exposes Real Addresses Behind Aliases

Researchers have disclosed two unpatched de-anonymization vulnerabilities in Apple's iCloud+ Hide My Email proxy service. Despite a year of private disclosure and two claims of remediation by Apple, the flaws remain active and allow attackers to resolve masked aliases back to users' real email addresses.

Security Boundary Failure in iCloud+ Mail Relay

Apple's Hide My Email service functions as an anonymous SMTP forwarding relay. It is designed to provision unique, randomized intermediate addresses—such as `random.email.22@icloud.com`—to act as a buffer that masks a user's destination inbox, such as `realname@example.com`.

Security researchers Ben and Tyler, co-founders of EasyOptOuts, discovered two distinct vulnerabilities that break this isolation layer. The flaws allow an external attacker to resolve the underlying destination address of any active Hide My Email proxy. Apple has confirmed to the researchers that the service design is not intended to permit the discovery of hidden addresses, confirming that this behavior represents a direct breach of the service's primary security guarantee.

Failed Remediation and Disclosure Timeline

The vulnerabilities have remained open for over a year due to repeated regression and verification failures during the private disclosure process.

  • June 11, 2025: EasyOptOuts discovered the primary vulnerability and submitted the initial report to Apple.
  • June 13, 2025: Researchers provided Apple with comprehensive reproduction steps.
  • June 20, 2025: Additional telemetry and troubleshooting data were submitted to Apple.
  • July 9, 2025: A second, distinct vulnerability causing the same mapping exposure was identified and reported.
  • July 14, 2025: Apple officially acknowledged both vulnerabilities were under technical review.
  • March 3, 2026: Apple notified the researchers that a fix had been deployed and requested verification.
  • March 19, 2026: Regression testing by the researchers confirmed that the original exploit vectors remained fully operational.
  • May 22, 2026: The researchers identified a broader scope and heightened severity for the vulnerabilities and escalated the findings to Apple. This escalation received no official acknowledgment.
  • June 30, 2026: Apple again reported the issues as resolved. Secondary verification by the researchers confirmed the flaws were still unpatched.

Threat Mitigation and Current Status

Because the vulnerabilities remain unpatched, the technical details of the exploits are currently being withheld to protect the iCloud+ user base. The existence and impact of the flaws have been independently verified by journalist Joseph Cox of 404 Media acting as a trusted third party.

With no verified patch in place, the researchers opted for public disclosure to allow systems engineers and users to update their threat models. Suggested interim mitigation strategies for Apple's infrastructure team include temporarily disabling the generation of new Hide My Email addresses and issuing direct exposure notifications to the current user base until a verified patch is deployed.

Read the original article at easyoptouts.com.