Multiple outlets report that Apple has fixed a vulnerability affecting iCloud+’s “Hide My Email” feature. The issue was originally brought to wider attention after 404 Media described a flaw in which the feature did not fully conceal a user’s real email address. According to the reports, the vulnerability could allow other people to obtain “real” email addresses associated with iCloud+ Hide My Email aliases, undermining the privacy expectation of the service.
In response, Apple now states that the problem has been addressed. Engadget and 9to5Mac both report that Apple’s fix is in place, framing it as an official resolution to the previously reported exposure risk. Both sources characterize the bug as one that made emails “not especially hidden,” rather than claiming broader functionality failures or data loss. Neither report describes specific timelines for when the flaw was introduced, how widely it may have been exploited, or whether any particular users were confirmed to have been affected. The reporting focuses on the privacy impact and Apple’s assertion that the vulnerability has been corrected.