For many people living under the threat of stalking, harassment, or data exploitation, Apple's Hide My Email feature has represented something close to a lifeline. The tool, which generates disposable email addresses to shield a user's true identity online, is marketed as a cornerstone of Apple's much-celebrated privacy ecosystem. That sense of security may now be misplaced. A researcher named Tyler Murphy has confirmed that a vulnerability in Hide My Email allows those disposable addresses to be traced directly back to the real addresses they were designed to conceal — and that Apple was warned about the problem more than a year ago.
Murphy, who is co-founder of EasyOptOuts, a paid service that removes personal data from broker websites, disclosed his findings to the outlet 404 Media after growing frustrated with Apple's apparent inaction. Every single attempt to exploit the flaw succeeded. "Publicly accessible people-search sites make it easy to link an email address to other personal details, so people relying on Hide My Email for safety may be at risk," Murphy told 404 Media. The precise technical mechanism behind the vulnerability has not been made public, since researchers fear that wider disclosure would accelerate its misuse before a patch is released.
The flaw does not exist in isolation.