Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses

A security researcher discovered a vulnerability in Apple's Hide My Email feature that could expose users' real email addresses. The flaw, which Apple has since fixed, allowed malicious actors to bypass the privacy tool designed to shield users' actual email accounts when signing up for services or newsletters.

Background

- Apple's "Hide My Email" is a privacy feature (part of iCloud+ and Sign in with Apple) that generates unique, random email aliases so websites and services never see a user's real email address. Emails sent to the alias are forwarded to the user's real inbox. - A security researcher discovered that this protection can be bypassed: when a website requires email verification, the "verify your email" link sent by the website to the alias can contain the user's real email address in the URL, exposing it to the website or to anyone who intercepts that link. - The vulnerability primarily affects "Sign in with Apple" users, because the forwarding mechanism in some cases constructs verification URLs using the underlying real address rather than the alias. - 404 Media is a tech news outlet focused on digital security, privacy, and the culture of the internet, often covering vulnerabilities and platform failures like this one. - The issue matters because Hide My Email is marketed as a strong privacy tool; this flaw undermines that promise by leaking the very information it is supposed to conceal.

Related stories