For more than a year, one of Apple's core privacy tools was doing the exact opposite of what it promised: leaking users’ real email addresses.
Cybersecurity researchers found that the "Hide My Email" feature, a key privacy shield for iPhone, iPad, and Mac users, was fundamentally broken. The service is designed to create random email aliases to protect your identity. Instead, it was exposing it.
This vulnerability dismantled the very shield Apple built to protect its users from prying eyes.
The Core of the Vulnerability
"Hide My Email" is a central part of Apple's iCloud+ subscription, woven into services like "Sign in with Apple" to curb spam and bolster anonymity. Users depend on it to sign up for apps and newsletters without revealing their personal inbox.
Why This Matters: A Betrayal
This isn't just a bug; it's a betrayal. Apple sells privacy as a product, and for more than a year, that product was broken.
It means that every user who trusted this feature to protect their identity was left unknowingly exposed. This failure raises serious questions about how Apple audits the critical privacy features at the heart of its ecosystem.
The flaw’s longevity is especially troubling. Its existence for over a year suggests this wasn't a fleeting glitch but a persistent vulnerability.
That long window of exposure could have impacted countless interactions made by the very users who put the most faith in Apple's privacy promise.