Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses

A vulnerability in Apple's Hide My Email feature exposed users' real email addresses, potentially allowing senders to bypass the privacy protection intended to mask personal inboxes from third parties.

Background

- Hide My Email is an Apple privacy feature (part of iCloud+) that lets users generate unique, random email aliases (e.g., "abc123@icloud.com") to use instead of their real address when signing up for websites or newsletters. The idea is that the alias forwards to your actual inbox without revealing your real email. - A vulnerability was discovered: if a website uses the email alias as a login identifier and a user resets their password, the password-reset system (e.g., a "Forgot Password" page) sometimes prefills or reveals the underlying real email address to anyone who knows the alias. This defeats the purpose of the privacy feature. - The issue was reported to Apple but has not been fully patched; it depends on how third-party websites handle the alias in their own systems. This matters because it shows a gap between Apple's privacy promises and real-world implementation, and affects anyone using the feature to protect their identity from spam, tracking, or data breaches.

Related stories