Hasty Briefsbeta

Bilingual

How Apple's Hide My Email exploit worked and why you're still at risk

18 hours ago
  • Apple's Hide My Email service leaked users' actual email addresses in bounce error messages when emails were rejected as spam or due to other errors like deleted accounts.
  • The vulnerability was reported in June 2025 but took over a year to fix, with multiple unsuccessful fix attempts until July 2026.
  • Leaked email addresses were stored in third-party email logs (e.g., Mailgun), creating long-term privacy risks even after the bug was fixed.
  • The exploit was simple: send a spammy email to a Hide My Email address and find the hidden email in the 550 or 552 error response.
  • Apple did not notify users during the year-long vulnerability period, and only fixed it after public disclosure by 404 Media in July 2026.
  • Users are advised to assume their email was leaked, deactivate old Hide My Email addresses, and consider using alternative aliasing services.