iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Ai ›› Llms ›› Apple's Hide My Email Vulnerability Exposes User Addresses for Over a Year

Apple's Hide My Email Vulnerability Exposes User Addresses for Over a Year

A vulnerability in Apple's Hide My Email service has been leaking users' real email addresses for at least a year, according to security researcher Tyler Murphy. In tests, all Hide My Email addresses were exploitable. Apple has acknowledged the issue but it remains unpatched. This story is part of a broader security roundup covering Pegasus spyware, Google's EU warnings, Meta chatbot testing, and the arrest of a Scattered Spider hacker.

iG
iGEN Editorial
July 4, 2026
Apple's Hide My Email Vulnerability Exposes User Addresses for Over a Year

This week's security news is dominated by a critical flaw in Apple's privacy-focused Hide My Email service, alongside developments in spyware, AI abuse, and hacking groups. A WIRED investigation also revealed Meta contractors posing as minors to test chatbots, and a researcher used Anthropic's Claude Opus 4.7 to hack a ticket site.

Apple's Hide My Email Flaw Exposes Users

Back in 2021, Apple launched its Hide My Email tool, which generates "unique, random email addresses" that forward incoming messages to a user's personal inbox, reducing the amount of information shared with online services. However, 404 Media reported this week that a vulnerability in the system has made it possible, for at least a year, for people's real email addresses to be uncovered.

Security researcher Tyler Murphy, who discovered the flaw in June 2025, told the publication: "Apple Hide My Email is leaking email addresses that are supposed to be hidden." He added, "In our limited tests with volunteers, 100% of Hide My Email addresses were exploitable."

The exact details of the vulnerability have not been revealed as the problem remains unpatched. In tests conducted by 404 Media and Murphy, a newly created Hide My Email address using the @icloud.com domain could be linked back to the real email address of its creator. Murphy originally reported the problem to Apple last summer and was told it had been "addressed" by March this year, but further testing showed the issue remained exploitable. Months ago, Apple told Murphy it was still investigating. Apple did not respond to requests for comment from the publication.

Aspect Detail
Discovered by Tyler Murphy (June 2025)
Exploitability 100% of tested addresses exploitable
Reported to Apple Summer 2025; told "addressed" by March 2026, but still exploitable
Current status Unpatched; Apple still investigating

Politician Targeted with Pegasus Spyware

A politician on the European Parliament's PEGA Committee—created to investigate spyware abuses, including the notorious Pegasus malware—was targeted with Pegasus himself, according to new research findings released this week. This underscores the ongoing threat posed by commercial spyware to high-risk individuals.

Google Warns EU Rules Could Weaken Security

Top Google security staff warned this week that the pro-competition rule proposals in the EU could make Google Search and Android systems vulnerable to hacking and other abuse. The warning highlights the tension between regulation and security in the tech industry.

Scattered Spider Member Arrested, Others Plead Guilty

A nineteen-year-old has been arrested and extradited to the United States to face charges over their alleged involvement in the notorious Scattered Spider hacking group, the Department of Justice (DoJ) announced this week. Peter Stokes, an Estonian-US dual citizen, was arrested in Finland in April and has been charged with computer intrusion, conspiracy, and fraud.

It is alleged that Stokes, along with other members of the loose hacking collective, hacked into an unnamed "luxury jewelry retailer" and demanded an $8 million cryptocurrency ransom in May 2025. The company did not pay but still spent $2 million on the incident, according to a DoJ press release. In recent years, Scattered Spider, largely believed to be composed of young, English-speaking teenagers, has caused havoc worldwide by hacking and disrupting dozens of businesses. The arrest of Stokes follows two British Scattered Spider members, Thalha Jubair and Owen Flowers, recently pleading guilty to hacking Transport for London in 2024 and causing millions in damages.

Additional Security Highlights

A WIRED investigation revealed that Meta contractors posed as kids and teens to see how chatbots like Gemini and ChatGPT responded to prompts about high-risk subjects, including suicide, sex, and drugs. This raises questions about the safeguards in AI systems.

Meanwhile, a researcher realized he could use Anthropic's Claude Opus 4.7 to break into the website of Front Gate and issue tickets to almost any United States music festival, including Lollapalooza and Bonnaroo, demonstrating the potential for AI to be exploited for malicious purposes.

Finally, WhatsApp has announced it will soon roll out usernames to billions of people, allowing connection without sharing phone numbers and increasing privacy protections. However, officials in India have raised concerns about the feature's implications for regulation and law enforcement.

These stories collectively underscore the evolving threat landscape in cybersecurity, affecting enterprises, governments, and individuals alike. For enterprise technology decision-makers, the Apple Hide My Email flaw is a stark reminder that even privacy-focused tools can have critical vulnerabilities, while the Scattered Spider case highlights the persistent risk of financially motivated hacking groups targeting companies.


Sources: WIRED – Security

Keep Reading

Recommended Stories

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call Technology

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

Researchers at A Security uncovered Zoom screen-sharing vulnerabilities using publicly available AI models, enabling silent device takeover on any supported platform. Fewer than 20 prompts were needed to create a working attack. Zoom has issued server and client patches, but the disclosure highlights the democratization of AI-driven hacking.

August 11, 2026
Reverse-Lookup Service Exposed Millions of Photos of People's Faces Technology

Reverse-Lookup Service Exposed Millions of Photos of People's Faces

Independent security researcher Jeremiah Fowler found that the people-search service ClarityCheck left more than 9 million image files, including photos of faces, publicly accessible in an unsecured Amazon S3 bucket. A second misconfiguration exposed email addresses and phone numbers. The company secured the data after WIRED reached out but disputed that the data was publicly exposed.

August 19, 2026
Sensitive Info Goes Into 'No Reply' Emails Constantly. This Guy Sees It All Technology

Sensitive Info Goes Into 'No Reply' Emails Constantly. This Guy Sees It All

Security researcher Cory Solowewicz inadvertently created a honeypot by owning noreply.us and noreply.net, collecting hundreds of thousands of misdirected emails containing sensitive data. He has been alerting affected companies and presenting his findings at Defcon. WIRED reports he has received more than 400,000 messages on one domain alone.

August 8, 2026
OpenAI's Browser Could Be Hijacked to Spam Your WhatsApp Contacts Technology

OpenAI's Browser Could Be Hijacked to Spam Your WhatsApp Contacts

Security researchers at Zenity demonstrated that OpenAI's Atlas browser can be tricked into spamming WhatsApp contacts and manipulating Amazon shopping sessions. The findings, presented at Black Hat, are part of a broader discovery of about 20 flaws in AI-enabled browsers from major tech companies.

August 5, 2026