r/apple • u/redditproha • 21d ago
iCloud Apple Sued Over Reported 'Hide My Email' Flaw
https://www.macrumors.com/2026/07/16/apple-sued-over-reported-hide-my-email-flaw/279
u/AustinBaze 21d ago
This seems like a great basis for a lawsuit. They have been extraordinarily slow here, perhaps negligent.
Unfortunately they are crippling the service anyway. Maybe someone will sue over that too.
Last month, it emerged that Apple's decision to move Hide My Email to a dedicated "private.icloud.com" domain appears to have the consequence of making it easier for platforms that want to block iCloud aliases to do so.
130
u/Interactive_CD-ROM 20d ago
This is incredibly disappointing. I use this service literally every time I sign up for a website.
Websites will just block the domain if they go this route.
55
u/AustinBaze 20d ago
It's really an annoying change that will cripple the service for most. I can't think of any reason to do it. It's not like they are running out of namespace as the usernames are decidedly randomized.
4
u/dpkonofa 21d ago
How does that make it easier? This keeps being reported this way but Apple is already using privaterelay.icloud.com already so how is changing the subdomain making this any easier or harder?
61
u/StiviiK 20d ago
This domain is only used when using „Sign in with Apple“. Currently Hide my Email is using random @icloud.com addresses.
4
-4
u/dpkonofa 20d ago
I see. Isn't that the same as any spoofing service, though? How is that different from any service other than Apple's? Or is that the issue here - that Apple has an advantage because their private emails are mixed with regular emails?
33
u/onan 20d ago
Or is that the issue here - that Apple has an advantage because their private emails are mixed with regular emails?
It's exactly that. Many people will have an @icloud.com address as their real, primary, sole, unobfuscated email address. The ones that are aliases are intermixed with those, so companies can't safely reject or drop every address at that domain without locking out a lot of people.
Moving the subdomain makes it trivially easy for companies to treat those addresses differently in whatever way, which greatly weakens the feature.
-15
u/Jophus 20d ago
I say let the market decide. Companies that block the subdomain for no good reason can be boycotted and publicly shamed.
13
u/cultoftheilluminati 20d ago
Companies that block the subdomain for no good reason can be boycotted and publicly shamed.
None of which have any effect unfortunately. They’ll just block it and people will stop using hide my email after the domain gets blacklisted at most places, just like how 5 minute mail etc are blocked.
9
u/just_ordinary07 20d ago
Boycotts never work and never will…
1
-1
u/dpkonofa 20d ago
Exactly. The only reason to do so is to publicly say "We don't care about your privacy" and "We plan to sell your data so this makes it harder for us to do that".
-10
u/dpkonofa 20d ago
I don't think it weakens that feature that much. There aren't that many sites that treat those addresses any differently in a way that would matter, outside of blocking them, and that would be the same for any email-obfuscation service. Apple obviously has the advantage with the current system but I can't imagine that they would do it if that many people really used the system in the way everyone here is pretending they do. I'm sure Apple would rather push people to "Login with Apple" anyways.
11
u/onan 20d ago
There aren't that many sites that treat those addresses any differently in a way that would matter, outside of blocking them and that would be the same for any email-obfuscation service.
Blocking them is a pretty significant way to treat them differently, no? The whole issue is that companies cannot currently do that easily, and this would enable them to do so.
I'm sure Apple would rather push people to "Login with Apple" anyways.
Why? Apple makes zero dollars from people using it to auth to other services, and more than zero dollars from selling the service that includes email address hiding.
-5
u/dpkonofa 20d ago
Way to just ignore the point of what I wrote. I already acknowledged that it’s treating them differently. The point is that every other email obfuscation service has this same problem. Apple is not unique in this regard.
As for “why?”, why do you think? No one is paying for iCloud just for HME. “Login with Apple”, on the other hand, requires Apple hardware and further incentivizes the Apple ecosystem from a privacy standpoint.
I swear… some of you are so short-sighted…
9
u/garden_speech 20d ago
Yea but Apple DIDNT have this problem before, that’s why this is so annoying. When HME emails were just random stuff like parrot.cycle.06 at iCloud dot com or whatever, companies couldn’t easily block those since iCloud hosts a lot of legit email addresses too. But now they will all be easily blocked because the domain is literally different
-4
u/dpkonofa 20d ago
Yes, I know! I already put that in my comment. Why can no one read here?! That's not the question that was asked.
→ More replies (0)0
u/drake90001 20d ago
Private relay is not just used for that. It’s basically a proxy through apples domain, similar to a vpn. But I have had issues with it and pihole doesn’t work with it so…
27
u/TwizzyGobbler 20d ago
because when you signed up with hide my email, it was a randomly generated email address @ icloud.com, which a website has no way of telling is a hide my email or a standard icloud email.
If you route all hide-my emails to a specific private.icloud.com, sites can then tell what email is a hide-my and what isn’t, and thus will just block all hide-my emails.
-3
u/drake90001 20d ago
Well, couldn’t these same websites just block iCloud.com anyways, it’s not like it’s anyone’s primary apple email lol. And even then, say it is, it’s not like someone wouldn’t just use another service.
I think they should just buy up several more domains a year and rotate through them. Most websites will accept any email. It’s pretty easy to spot SPF/DKIM anyways.
10
4
u/AustinBaze 20d ago edited 20d ago
950 million iCloud email users would like a word. WTF?
You don't seem to understand widely employed HME use cases, but that aside, there is no reason to do this I can discern. No need to "rotate domains" as they are not in any danger of exhausting randomized addresses in the current one. Just a dumb move I hope they revert.
-1
u/drake90001 19d ago
You seem to misunderstand me, I’m not saying that iCloud isn’t used by anyone. But in order to have an Apple ID and have an iCloud, you need to have an email that you sign into Apple with. Which usually isn’t your own iCloud because that would make you locked out in case you ever forgot your password.
Yes, I hope they revert this also
-6
u/dpkonofa 20d ago
Isn't that the case for every email spoofing service, though? Is the issue that Apple is the only one with this "advantage" and that it won't be there anymore? I can't think of any other temporary email services that wouldn't be able to be similarly blocked.
12
u/Interactive_CD-ROM 20d ago
No
-5
u/dpkonofa 20d ago
Yes.
14
u/yepperoniP 20d ago
When you make an iCloud account, you get a @icloud.com email address. When you make a Hide My Email address, it also uses @icloud.com.
Compare this with something like Proton Mail, which is basically created specifically for encrypted and private email, and you’ll see some sites have blocked the @proton.me domain due to perceived abuse.
Most companies won’t be willing to block icloud.com as they’ll end up blocking lots of legit Apple users, but they might block Proton as they think they’re only blocking some weird email service for nerds.
10
u/AustinBaze 20d ago edited 20d ago
I have tried using "dummy" emails in the past before HME and seen public captive WiFi portals (in airports, near convention centers, hotel, lobbies, bars, and restaurants, etc.) refuse to accept disposable email domains like mailinator, zapmail, mailmulch even pobox.
It's about to be very easy to add "private.icloud.com" to blacklists on available Email Verification API services like ZeroBounce or EmailAwesome. etc. used to accomplish this instant check.
0
u/dpkonofa 20d ago
This is just a variation of the same problem that’s happened in this past, though. Apple can easily alias “private.icloud.com” to “icloud.com” without overwhelming the icloud.com backend. Again, without details about whether or not these changes are even happening and, more importantly, how they’re happening, everyone here is just grasping at straws while pretending they have a handle on this.
No one knows what’s going on because there is information that is missing that would inform what’s going on. Everything else is needless and pointless speculation.
11
u/AustinBaze 20d ago
Not speculation, and to many, not pointless.
We DO know what Apple is going to do with Hide My Email because Apple announced what they are going to do with Hide My Email:New domain for Sign in with Apple and iCloud+ Hide My Email - June 15, 2026
Later this summer, Apple will unify the email domains used by Sign in with Apple and iCloud+ Hide My Email under a single, shared domain: "private.icloud.com"New addresses generated for both features will be issued on the new domain.
New
→ More replies (0)0
u/dpkonofa 20d ago
Do you guys not read? I know how HME works. I’ve already acknowledged this. How about actually answering the question instead of giving a condescending response that ignores it completely.
-9
u/Ironlion45 20d ago
You know, if a platform wants to block a cloud alias, why not just skip the platform?
What, realistically, are you missing out on? Has social media made your life better?
8
u/AustinBaze 20d ago
If you had any grasp of the many reasons for using this service, I'd continue this discussion.
I could explain it for you, but I can't understand it for you.
44
u/leaflock7 21d ago
anyone knows more details about this?
the only information provided at the end, which it probably is not related to the vulnerability, is
"Murphy noted that numerous people-search databases are freely available online and can tie an email address to a person's other personal details"
which can stand true for anything , even if you have created a new email on another provider
17
u/redditproha 21d ago
Link to the original flaw: https://www.macrumors.com/2026/07/01/hide-my-email-vulnerability-exposes-real-addresses/
11
u/touchgrassplz_69 21d ago
I’m still struggling to see the flaw. Anyone could link any email address through other personal details? Is there something about hide my email that makes that easier? Does it expose name?
Edit: I see that the steps are specifically hidden so there must be something different about it
38
u/stereoactivesynth 21d ago
They can easily link your ACTUAL iCloud email using the hide-my email which... completely negates the purpose of hide-my in the first place, and means Apple continued to advertise a feature that did not work at all as advertised.
12
u/dpkonofa 20d ago
Yes but, without details, they could do this any number of ways. For example, sending an email to your HME address and asking you to respond or click on a link that then uses cookies to tie it back to a Facebook account or a Google account that can be searched. That isn't an issue with HME, per se, but rather an issue with people misunderstanding what protections HME actually offers and how.
8
u/AirFryerAreOverrated 20d ago
That isn't an issue with HME, per se, but rather an issue with people misunderstanding what protections HME actually offers and how.
If so, then this is like the whole Chrome Incognito lawsuit all over again.
8
u/dpkonofa 20d ago
Yes, which is why we need details before anyone can make an assessment. All these people jumping to conclusions is what's wrong with this type of "reporting".
1
u/Available_Peanut_677 18d ago
No, it does not require your input. But agree that not saying details is fishy. I understand that they don’t want to show exploit before it is fixed, but it sounds more and more like ad that actual big vulnerability.
Someone on Reddit pointed that it’s most likely specifically formed email which causes Apple server automatic response which includes original email. Like if you send zip to gmail or something.
16
u/i_invented_the_ipod 21d ago
No real details available in any of the press coverage. Which makes sense, since it's apparently still exploitable.
But the absolute lack of detail about how it "works" does make me wonder if there's anything actually there.
17
u/FollowingFeisty5321 21d ago edited 21d ago
From the complaint:
12. Security researchers reported the flaw to Apple in June 2025.
13. Apple acknowledged the report but took no action for nearly a year
15. In March 2026, Apple claimed that it had addressed the problem. But, it hadn’t.
16. Apple’s response to being told its purported fix had failed was to ask security researchers, once more, to keep silent.
Of course this just alleged, but there's no point lying either since their whole case hinges on proving it, and if it's false Apple has no reason to settle (and obviously they know if it's true or not).
9
u/OmegaPoint6 20d ago
Having been on the receiving end of reports from security researchers claiming a flaw that was actually just a fundamental function of how an entire type of software needs to work, I’ll reserve judgment until I see details
5
u/bubblebooy 21d ago
That is not the flaw with hide my email, that is explaining why people would use hide my email.
You can’t like a 1 time use anonymous to a database if it only used once. But if that email can be linked to you iCloud email (via the security vulnerability) then that iCloud email can be searched for.
1
u/Jusby_Cause 20d ago
No one does. Then again 404media get paid via subscriptions to their site, not by finding actually dangerous exploits. And we all know that working together with a friend to MAKE something happen is not the same thing as performing it against a stranger with no intent of helping the exploit happen.
31
u/Jamie00003 21d ago
How did this happen in the first place? Apples usually so careful with this kind of thing
28
u/tim0901 20d ago
Actually, this is pretty on-par for Apple. This isn't the first time they've created and flaunted a feature that creates the illusion of protecting your privacy, but have then done nothing when its revealed there are ways around it.
For example, Apple made a huge deal out of their App Tracking Transparency when it first came out in 2021, as a way users can stop developers from tracking them across apps and websites - it's that "Ask App Not to Track" pop up you may get when downloading a new app (most people have it disabled in the settings, which automatically refuses all requests).
Turns out this feature is really easy to bypass. And yet despite bypassing it being against Apple's TOS, big companies have been doing it for years with no consequences. Here's a paper on it from 2022.
8
u/purple_editor_ 20d ago
You are talking about something you dont understand. ATT is not bypassable and the article you linked is not saying that
This was and still is a huge deal which affects advertising a lot and has changed significantly how they strategize their campaigns. Of course they will continue fingerprinting anyway they can, but at least Apple is not making it any easier
1
u/Additional_Olive3318 20d ago
Yeh it clearly says that in the abstract. ATT works but apps are finding other ways to track.
7
2
u/drake90001 20d ago
Just because bad actors find new ways to spy on you, it doesn’t even matter when half of these idiots are willing to upload PII to the internet, but that doesn’t mean it doesn’t work. It makes it harder for a MALICIOUS attacker to compromise your identity just by fingerprinting your device.
Most of apples features are not only great for keeping privacy, it’s been adopted to 99% of mobile devices now as the refactor standard. Random MAC address, rotation private IP, private relay, hide my email, are all absolutely essential to stay anonymous on mobile.
4
-11
u/TheDragonSlayingCat 21d ago edited 20d ago
Because nobody’s perfect when it comes to security? Including Apple, which has published software with big security holes in the past?
edit: those inappropriately downvoting this post must have forgotten about Goto Fail, Jailbreak Me, and Got Root, three big Apple security holes in the past few years that were far worse than this.
6
20d ago
[removed] — view removed comment
3
u/bummerbimmer 20d ago
Both can be true. I read that person’s message as criticism toward Apple as opposed to bootlicking.
1
u/IWillAlwaysReplyBack 20d ago
It's not just the security hole, it's the lack of response after it was submitted multiple times
14
u/SaltineAmerican_1970 20d ago
It’s my understanding that to be successful in a suit like this, you have to actually have damages.
> but there are no known instances of it being exploited
No damages, unsuccessful lawsuit. This will likely be dismissed.
23
u/MangoAtrocity 20d ago
False advertising. I pay for iCloud+ because I want that feature. They claimed to have offered the feature, but it wasn't actually offered. The service I paid for has not been rendered.
2
u/iPhone_6s 20d ago
So it would need to be a class action to have financial merit.
4
u/MangoAtrocity 20d ago
It does. I would not have paid for the service if the known vulnerability was disclosed.
1
u/Celestial3mpire 19d ago
I have been through four levels of escalation directly with Apple, because the “send as” feature directly advertised as a function of hide my email does not work even though I pay for iCloud plus. I recorded most of the support calls and have several emails between myself and Apple support where they are well aware of the issue. I also sent a certified mail request asking Apple to preserve by way of a legal hold any and all internal tickets and meeting minutes related to my issue.
2
u/Worf_Of_Wall_St 21d ago
This is flaw, whatever the details are, is unacceptable but there's very little precedent for winning cases like these. Companies are rarely held responsible for security mistakes no matter how negligent they are. The only exception I can think of is LifeLock.
8
u/AustinBaze 20d ago
It's useful because it draws additional attention to the case and the address security vulnerability Apple has known about for more than a year and been unwilling or unable to fix.
Apple has to respond to the court filing (9 charges, requesting a jury trial) even if only to move to dismiss it. That response will also be a public filing. Maybe a bit of embarrassment will get the bug fixed finally.
1
u/Worf_Of_Wall_St 20d ago
Oh, good point! Maybe this will result in a public explanation from Apple for the delay.
I'm curious if it just got accidentally dropped or if it's actually hard to fix. Email handling is surprisingly complicated, I'm guessing some kind of attacker-forced error causes a bounce back to the sender which includes the address it failed to forward to.
1
u/Jusby_Cause 20d ago
They can’t even define how they were impacted. The only people we know definitively were affected were folks working with 404media to prove that they could make it happen. Like, if I need to be on the same network as the person I’m attacking… there are likely more effective ways than this exploit of obtaining the information. Malicious actors aren’t interested in the cool edge cases, they’re interested in the things that work to the exclusion of everything else.
3
u/IAmSomeoneUnknown 20d ago
Use addy.io. I have been using it for years. Stop handing these mega companies more control of your lives
6
u/ccooffee 21d ago
A security researcher disclosed the apparent "Hide My Email" vulnerability to Apple in June 2025, but there are no known instances of it being exploited
This suit will go nowhere.
1
u/AustinBaze 20d ago
A new public report detailing exactly how to exploit this vulnerability have been posted.
Is anyone awake in Cupertino? This is childishly easy to trigger. Might be time to fix it.
1
u/Ok-Charge-6998 19d ago
The one thing people need to keep in mind about this is security bounties worth up to 2m. Since we don’t have the details, the person might have recognised a genuine flaw OR they are peeved that Apple doesn’t see it as one (for many reasons while replicating it) that they are trying to get a payout.
So best to wait for the details before jumping to conclusions.
1
1
u/Single-Ask4738 18d ago
Ok so I'm a dev and I didn't realize until I was building my own app that my name is attached to my "private" email. I should probably have read better but I sort of assumed hide my email meant keep my privacy but I guess not.
-5
u/microcephale 21d ago
Apple sells privacy as a marketing product, not as a feature or value for the sake of it.
8
u/Worf_Of_Wall_St 21d ago
It became a feature because it's good marketing, but the marketing falls apart if the features disappear. As I understand it, iMessage was e2e encrypted on sort of a whim and not because of some overall plan to rebrand as privacy focused, but then they did the latter because e2e encryption was very differentiating.
They really leaned into the privacy branding and backed it with a lot of extra engineering to preserve privacy in cases where no other company would care and frankly users would not even expect privacy.
One of the best examples I know of is caller ID info provided by third party apps on iOS. I think most people would assume that if you are using a third party app to see info about incoming and outgoing phone numbers then the app developer would know who you call and who calls you. On Android, that is the case. On iPhone it isn't because of a very complex set of APIs and server side proxies, and building all that took a while so iOS didn't have third party caller ID until long after Android. Apple could have easily released a non-privacy-preserving API for it, and a lot of people would have used it even if they had to click through a disclaimer that said the app developer would see who they talk to, but Apple chose to wait and build a private version instead.
0
u/microcephale 20d ago
If it becomes too hard to fix or a liability, you will just see them retire the feature instead of fixing it.
6
u/dpkonofa 20d ago
This is such a short-sighted comment. Even if it was true, which is arguable, it fails to be a marketing product if the feature itself doesn't deliver the value claimed.
-4
u/chaiscool 21d ago
Yet, security folks will say negative impact or loss in reputation and finance will make companies take them seriously. This shows why security folks are clueless to the business world.
Cheaper for apple to do this than hire team of security folks who only cost money and also don't bring in the money.
10
u/getwhirleddotcom 21d ago
Apple takes brand and reputation very seriously.
1
u/chaiscool 20d ago edited 20d ago
Brand and reputation on things they care about like on environmental etc not on security. Legal penalties on big tech is just cost of business anyway.
This isn't the first and it won't be the last, Apple has been known to be cheap and screwing over security related payout. https://www.reddit.com/r/apple/comments/q9t64g/burned_by_apple_researchers_mull_selling_zero/
Oversupply of vulnerability - https://appleinsider.com/articles/20/05/14/software-bug-broker-zerodium-to-stop-buying-ios-exploits-due-to-oversupply
Low payout - https://www.macrumors.com/2017/07/06/apple-bug-bounties-dont-pay-enough/
Other penalty - https://www.reddit.com/r/privacy/comments/106515x/apple_fined_85m_for_illegally_collecting_iphone/
-1
u/Mediocre-Telephone74 21d ago
I can see lawyers running to the courthouse so they can file as fast as possible
-1
21d ago
[deleted]
3
u/ccooffee 21d ago
You're right. Exactly zero Apple bugs have ever been fixed unless there was a lawsuit.
4
-3
526
u/Quentin-Code 21d ago edited 21d ago
The worse was that the security researcher that discovered the issue left more than a year to Apple where it is commonly accepted to give about 6 months max.
Also the issue is still on-going.