9 ms·
Apple 'Hide My Email' vulnerability reveals peoples' real email addresses
https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/ https://www.404media.co/apple-hide-my-email-vulnerability-re..., https://archive.vn/mCbBw https://archive.vn/mCbBw
- tjames7000 3mo agoWe put up a timeline of the disclosure here: https://easyoptouts.com/guides/apple-hide-my-email-is-leaking-email-addresses https://easyoptouts.com/guides/apple-hide-my-email-is-leakin...
- dang 3mo agoThanks! We'll make that the main URL and put the submitted link in the toptext.
- culi 3mo agoThanks for everything y'all do with Easy Opt Outs. I've put a number of family members and acquaintances onto it. I'm glad this service exists at an actually affordable rate
- jijijijij 3mo agoCan you comment on this: https://news.ycombinator.com/item?id=48752294 https://news.ycombinator.com/item?id=48752294 ? To me it seems, at least in this instance there is not even an exploit needed and the feature apparently is just broken beyond belief.
- js2 3mo agoCan you please clarify whether this is only an issue if I reply to an email sent to one of my HME addresses or whether you can unmask any HME address w/o needing a reply from the recipient. Can you also clarify whether it matters what the forwarding address is? e.g. whether my HME addresses forward to an icloud.com address (e.g. js2@icloud.com) or say a personal domain associated with my Apple ID (e.g. js2@example.org).
- lode 3mo agoarchive link: https://archive.vn/mCbBw https://archive.vn/mCbBw
- FabHK 3mo agoThat's disappointing, both that the vulnerability exists in the first place, and that Apple takes over a year to not even fix it.
- chrisjj 3mo agoNot as disappointing as the discover's decision to leave affected users ignorant and hence at risk.
- kevin_thibedeau 3mo agoThey're a struggling company and can't hire top talent.
- deleted 3mo ago[deleted]
- bubbi 3mo ago[dead]
- rubatuga 3mo agoIs it based on mail undeliverable errors? Or attempts to login using IMAP or SMTP with it? Or is it exposed during the SMTP protocol?
- hunter2_ 3mo agoAs someone who doesn't rely on this feature, I'd love to know now as well, but perhaps the etiquette in public would be to align ourselves with: > we will not discuss or disclose the details of the exploits until they're fixed. But if there's a public forum where the cat's already out of the bag, then game on. Perhaps this: https://www.reddit.com/r/apple/comments/1ukilw1/apple_hide_my_email_vulnerability_reveals_peoples/oux8arw/ https://www.reddit.com/r/apple/comments/1ukilw1/apple_hide_m... ...which makes it seem like perhaps the attack surface is limited to scenarios involving a Yahoo/Sonic address (assuming that Apple only sends X-Sonic-* headers when talking to those providers that want to see it), which might be a small percentage of users.
- deleted 3mo ago[deleted]
- Dibby053 3mo agoMy guess would be it has nothing to do with email itself. Maybe it's some iCloud API that accepts obfuscated emails but returns the original email in the response, or an ID which can be used to retrieve the iCloud email from another API endpoint. Could be as simple as an "add contact/friend" feature in some Apple product (like a mail client, or a file sharing service) that resolves the obfuscated email to the original iCloud account.
- jijijijij 3mo agoI think they are hinting at the ad hoc "use hidemyemail" feature within e.g. the mail client. I don't know what I am doing, but from a quick test, the mail header is at least disclosing the internal recipient (mail@host.com) "translation address" (as mail_at_host_com_12345abc_12345abc@icloud.com) and an alias creation date. But the latter seems to be a unix timestamp related to the real address alias creation time and is identical between an hidemyemail mail and a normal one, so there may be already a possible information leak for correlation. Side note, it also seems like the sending hidemyemail server contains the unsuspicious name "junk_forwarder". Lol. Disclosing an address as alias and particularly as throwaway alias (through the translation address and server) already seems kinda counterproductive to begin with, but I would bet you can use this information somehow to get the sender "translation address". Either by some API interaction, or by messing with the mail header scrubbing of the translation service somehow. A server named "junk_forwarder" may be a little more lenient about what to accept or not. Edit: Can confirm the Reddit comment linked. You simply send an email to the HME address, reply from Apple mail client, and then the real mail address gets disclosed. Mind you not even hidden. It's shown as sending from the HME alias in mail, but I received the mail with the real address as sender......... Jesus fucking christ, Apple. Did you even test this a little?
- fsuts 3mo agoI think you should formally write to Apple and give notice of 30 days to contact you or you will reveal it. Send it to the USA media and regulator too
- tjames7000 3mo agoI've been going back and forth with Apple about it for a year. We don't feel comfortable releasing the exploit details even though they're being slow. We think enough people rely on Hide My Email for personal safety that it would be irresponsible.
- chrisjj 3mo ago> We think enough people rely on Hide My Email for personal safety that it would be irresponsible. I am guessing you haven't tried that excuse on the users your witholding is leaving exposed.
- tjames7000 3mo agoWe're hoping that by notifying people that there's a vulnerability, people can stop using Hide My Email if it matters to them. I don't think that disclosing the exploit method will get Apple to fix it faster at this point.
- chrisjj 3mo agoThe problem there is users cannot evaluate if it matters to them whilst all information needed to do so is being witheld.
- ezfe 3mo agoIf having your personal email exposed would be a matter of personal safety or similar, then stop using it. If you're just using it for junk mail or to get a free trial then keep using it.
- jijijijij 3mo agoI think "real email" address is underselling it, since that's commonly the apple-ID, which is the gateway to some people's whole digital existence. Not to mention the fact, you tend to use hidemyemail in particular for services you don't want any identity leaked to. The "real email" may contain your legal name already.
- deleted 3mo ago[deleted]
- alwa 3mo agoIt’s hard for me to assess how real this risk is. Without details, we’re just extrapolating from circumstantial vibes. What’s described sounds like it might be spooky. It might also be a magic trick to some degree… Mr. Cox’s PoC—“I gave a fresh Hide-My-Email alias to a guy who knows who I am, and he told me the email on my Apple ID”—is consistent with the claimed behavior but not exactly watertight. It also sounds like it might be the sort of thing that’s either “just how the email ecosystem works” or mitigable by covert means. For example, if Apple can identify exploit attempts from its privileged vantage over its infrastructure, maybe that’s the basis for its relaxed impact assessment. I’m reminded of Amazon’s risk assessment with respect to some Quick bug recently [0]: “yeah, it’s bad, but we checked and there are literally zero people other than you who’ve ever used that feature that way.” Or maybe it’s the kind of thing that requires a structural sort of tradeoff to conclusively fix. I could imagine the exposure mechanism having something to do with their forthcoming move to segregate aliases to their own “private.icloud.com” domain. (A move at which Mr. Cox swipes in the 404 Media article, too, of course, but hey—“impact journalism.”) And then, since we have only vibes to go on, there’s the judgment reflected in the researcher’s email to Apple: > “It seems that ending new sales of Hide My Email until the problem is fixed would be an effective way to limit the number of customers at risk. Is that an option?” Murphy wrote back. I can only hope that was a sardonic moment of frustration quoted out of context… Hide My Email is “sold” as a tiny tiny bonus feature of a much bigger iCloud+ product. But as-quoted, it’s giving a little bit of Chicken Little… I’m reminded of the time somebody demanded that a firm I’m familiar with halt all sales (and pay hush money) because of a CRITICAL SECURITY HOLE: you could access the contents of a password field by typing the password in the field, pressing F12 in the browser, and typing $(“#pw-input”).value … If the flaw really is the sort of thing that required fundamental product changes to fully address—like this domain segregation thing—a year doesn’t seem wild at all to make that transition safely and at scale. Especially if they identified effective mitigations in the meantime. Then again, maybe they really are negligent… [0] https://www.theregister.com/columnists/2026/05/13/aws-patched-quick-auth-bypass-says-customers-werent-using-control/5240041 https://www.theregister.com/columnists/2026/05/13/aws-patche...
- tjames7000 3mo ago> > “It seems that ending new sales of Hide My Email until the problem is fixed would be an effective way to limit the number of customers at risk. Is that an option?” Murphy wrote back. > I can only hope that was a sardonic moment of frustration quoted out of context I didn't make my point clearly there, and I think it makes more sense in context, but it was a sincere suggestion that Apple could stop allowing new people to use Hide My Email. There are many other email aliasing services, so they wouldn't be depriving people of a unique offering. At the time, I wasn't aware that Hide My Email was only available as part of iCloud+. All I knew was that it wasn't free.
- mike-cardwell 3mo agoThat timeline was exactly my experience with Apple here - https://www.grepular.com/Apples_Protect_Mail_Activity_Doesnt_Work https://www.grepular.com/Apples_Protect_Mail_Activity_Doesnt... They don't seem to know or care what is going on with their own email systems.
- lapcat 3mo agoHas anyone seen Protect Mail Activity get re-enabled after you've disabled it? I wrote about that a few days ago: https://lapcatsoftware.com/articles/2026/6/6.html https://lapcatsoftware.com/articles/2026/6/6.html
- AnonC 3mo agoNot for me. I don’t even remember when (or since how many years ago) I turned off Protect My Email and turned on both Hide IP Address and Block All Remote Content. I still have these toggles as they are, despite the fact that I use beta releases as and when they’re released (currently still on iOS 26.x).
- LoganDark 3mo agoFetching any email content is always worse than blocking it, because the typical threshold for spam is "is this inbox monitored". If that is true, then blast it with spam. And fetching anything ever proves that the inbox is monitored.
- layer8 3mo agoMy impression as a Mutt user (which never downloads linked content) is that spammers don’t really care about whether an inbox is “monitored” or not.
- tyre 3mo agoAt least in Gmail, downloading content (e.g. images) is disabled by default for suspicious emails. There is no way for the sender to know if it’s monitored unless this is disabled by explicit user action.
- risyachka 3mo agoShameless plug https://github.com/webmonch/hide-my-mail-cloudflare https://github.com/webmonch/hide-my-mail-cloudflare
- sunnybeetroot 3mo agoWhy not just use cloudflare with catch all email routing?
- deleted 3mo ago[deleted]
- cedws 3mo agoThe value of Hide My Email, SimpleLogin is that you can blend in with the crowd. If you use your own domain then the domain becomes the common link.
- deleted 3mo ago[deleted]
- kittikitti 3mo agoI use this feature often and I'm very disappointed. Depending on the exploit, I'm awaiting to join a class action lawsuit. I'm constantly humiliated by believing Big Tech's security promises and I've had enough. I suspect that this is yet another intentional backdoor. When these security systems fail, people like me experience violence.
- cindyllm 3mo ago[dead]
- charlesfries 3mo ago"This is the one thing we didn't want to happen"
- ChrisArchitect 3mo agoRelated: Apple is about to make Hide My Email useless https://news.ycombinator.com/item?id=48559935 https://news.ycombinator.com/item?id=48559935
- Jbird2k 3mo agoAs someone who uses this feature I never send messages from a hide my email address as I only use it for random email signups. Am I still at risk of having my email exposed??? It’s also handy for using for free trials lol.
- maram 3mo ago[flagged]
- deleted 3mo ago[deleted]
- alexpc201 3mo agoI guess the vulnerability should work as follows (I haven't tried it), you send an email with a very large attachment to a "hide my email" address, the server that receives it (private.icloud.com) forwards it to the email server registered in iCloud which, being the very large attachment, sends a response email (from the real address) with the rejected email message. It's the first thing I would try.
- VladVladikoff 3mo agoYeah it’s a good guess. I was also thinking there might be some header leaks. Or possibly if you return server busy on the first attempt or something like this, some sort of edge case the developers overlooked.
- js2 3mo agoApple rewrites the From address of before forwarding so that replies go back through its SMTP servers. Those SMTP servers should rewrite the reply not to leak information.
- winstonwinston 3mo agoEven when it rewrites message envelope and headers, the actual message body of an NDR (nondelivery report) can disclose original address information. Because the NDR is generated by the receiver server, the HideMyEmail does not have influence on what the message body can contain. Think of it as if you had an out-of-office autoreply which includes your email address among other information in the message body.
- js2 3mo agoI've run decently sized SMTP servers in the course of my career. I have some idea how SMTP works. In my testing, Apple's HME SMTP servers do NOT sanitize the headers at all. If you setup HME to forward to a non-iCloud address, you absolutely risk leaking information if you reply to an HME email. For example, in my testing, the replies disclosed the DMARC policy I have on my domain when Apple's SMTP servers themselves added that header: X-DMARC-Info: pass=pass; dmarc-policy=reject; s=r1; d=r1; pdomain=mydomain.org (Where "mydomain.org" is my actual personal domain from which I replied when I had HME setup to forward to js2@mydomain.org.) So in that sense, I'm agreeing with you. But, that's not the claim that alexpc201 made. To wit: "sends a response email (from the real address) with the rejected email message" Sure, that's possible, but I doubt it and I was also unable to trigger such behavior. An oversized message is bounced directly by the receiving SMTP server with: message size 67539976 exceeds size limit 28311552 of server mx01.mail.icloud.com[17.57.154.33] I tried various approaches. They all bounce at the edge: Reporting-MTA: dns; mailfout.phl.internal X-Postfix-Queue-ID: 13B6AEC00E7 X-Postfix-Sender: rfc822; elided@pobox.com Arrival-Date: Thu, 2 Jul 2026 18:28:38 -0400 (EDT) Final-Recipient: rfc822; word-word.0x@icloud.com Original-Recipient: rfc822;word-word.0x@icloud.com Action: failed Status: 5.0.0 Remote-MTA: dns; mx02.mail.icloud.com Diagnostic-Code: smtp; 550 We are unable to send your email as one or more of its attachments may be corrupted or may contain malicious content. So the theory now has to be that possible to sneak something past the edge SMTP server, past the point where the system rewrites the HME address, then bouncing, and in sending the bounce, failing to properly rewrite something on the way back out, thus disclosing the real address. I remain skeptical that's what's happening. Elsewhere in this thread someone theorized that the leak doesn't involve SMTP at all, but maybe some other service Apple operates. --- Since doing this testing, I updated my HME setting to forward to my real iCloud.com address instead of my personal domain. If I then reply on icloud.com, nothing that I can see is leaked. So basically, the HME SMTP servers are: 1. Rewriting the From and To address in a reply. 2. Are not sanitizing message headers. 3. When replying from a non-icloud.com domain, are actually inserting new headers which leak information such as your domain if you have a DMARC policy setup. Eeek! So be careful when replying to an HME email! But even though the blog post is vague, I believe the claim is that no reply from the HME address is necessary.
- frollogaston 3mo agoOk, yet another reason I have a totally separate burner Gmail instead of complicating things like this.
- deleted 3mo ago[deleted]
- ljsocal 3mo agoI submitted your post to Apple’s feedback for on iCloud. If others do the same, perhaps they’ll take notice: https://www.apple.com/feedback/icloud/ https://www.apple.com/feedback/icloud/