Visualização de leitura

Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability

Hide My Email

Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide My Email as a privacy safeguard while continuing to charge customers for access through its iCloud+ subscription service.  The legal action follows a report from 404 Media that revealed a reported vulnerability in Hide My Email. The report claimed the flaw could allow someone to identify a user’s actual email address from the private relay address generated by the feature. According to the report, Apple had been aware of the issue for more than a year before releasing a fix. 

Hide My Email Vulnerability Becomes the Focus of Apple Lawsuit 

Apple confirmed that it deployed a patch on July 3, 2026, stating that the Hide My Email vulnerability had been fully resolved. However, the lawsuit alleges that Apple continued marketing the feature as secure while the reported weakness remained unresolved.  The complaint states that security researchers first informed Apple about the vulnerability in June 2025. Although Apple acknowledged the report, Anthony Alvarez’s lawsuit claims the company did not resolve the issue for nearly a year. The filing also alleges that Apple incorrectly stated in March 2026 that the problem had been fixed, even though researchers reported that the vulnerability remained exploitable. 

How Apple’s Hide My Email Feature Works 

Hide My Email was introduced with Sign in with Apple in 2019. The feature creates unique relay addresses for supported apps and websites, allowing messages to reach a user’s inbox without revealing the person’s actual email address. Apple later expanded Hide My Email through the paid iCloud+ subscription, launched alongside iOS 15 and macOS Monterey in September 2021. The iCloud+ version allows subscribers to create unlimited private relay addresses for websites, newsletters and email communication. The lawsuit argues that millions of Apple users relied on Hide My Email to reduce spam, limit online tracking, protect personal information from data brokers and avoid exposure during third-party data breaches. Researchers cited in the complaint said that once a real email address is revealed, it may be linked with publicly available people-search databases, potentially exposing identities and other personal information.

Anthony Alvarez Claims Apple Misled Customers Over Privacy 

The complaint argues that Apple built much of its brand identity around privacy, referencing marketing statements such as “Privacy. That’s iPhone,” “What happens on your iPhone, stays on your iPhone,” and descriptions of privacy as a “fundamental human right” and “core value.”  According to the lawsuit, Apple’s privacy messaging influenced consumer decisions and helped justify premium pricing for Apple hardware and services. The plaintiffs claim Hide My Email was promoted as a central part of those privacy commitments.  The filing alleges that Apple asked researchers not to publicly disclose details of the vulnerability instead of warning customers or temporarily disabling the feature. It claims users were never informed that their real email addresses could potentially be exposed while Apple continued presenting Hide My Email as a privacy protection tool. 

Lawsuit Seeks Damages and Changes From Apple 

Anthony Alvarez is seeking reimbursement for iCloud+ subscription fees and other alleged financial losses. The lawsuit requests an injunction requiring Apple to either provide the privacy protection promised through Hide My Email or clearly disclose any limitations.  The complaint includes claims involving California’s Unfair Competition Law, False Advertising Law and Consumers Legal Remedies Act, along with allegations of fraud, negligent misrepresentation, breach of contract, breach of implied warranty and unjust enrichment.  The lawsuit argues customers paid for Apple’s privacy protections in multiple ways, including iCloud+ subscription fees and premium prices associated with Apple devices marketed as offering stronger privacy features. Apple has stated that the July 3, 2026 patch resolved the Hide My Email issue. 

Apple Sued Over Hide My Email Privacy Claims

Apple faces a proposed class action alleging a Hide My Email flaw could expose users’ real addresses despite the company’s privacy claims.

The post Apple Sued Over Hide My Email Privacy Claims appeared first on TechRepublic.

Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself

A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the future of cybersecurity? Also, Apple's "Hide My Email" feature turns out to hide rather less than it promises - despite Apple knowing it has a problem for over a year. All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Zoë Rose.

Government and Healthcare Are the Weakest Links in Global Email Security

Government and healthcare sectors have weak email security. Many domains lack SPF, DMARC, DKIM, and MTA-STS, leaving them open to phishing attacks.

Comparitech analyzed live DNS records for 5,849 domains across 13 sectors and scored each one out of 8 points based on four standard email authentication protocols: SPF, DMARC, DKIM, and MTA-STS. The results aren’t flattering. More than 8 percent of organizations had zero protection in place, and only 0.6 percent — 33 domains out of 5,849 — scored full marks. That’s 33 organizations out of nearly 6,000 doing everything right.

Government came last, with an average score of 2.73 out of 8.

“121 out of the 452 domains we scanned had zero protections in place (27%)–the highest of all sectors.” reads the report published by Comparitech. “No government domains scored full marks, but three did score 7.5 – Australia’s national science agency (CSIRO), the Mila – Quebec Artificial Intelligence Institute in Canada, and The Alan Turing Institute in the UK (also dedicated to data science and artificial intelligence).”

China’s government domains averaged just 0.9, with 65 percent having no protection at all. France wasn’t far behind at 1.4 average and 47 percent unprotected. The UK and US were the best performers in the sector, but even 17 percent of US government domains had zero protection — despite a Department of Homeland Security mandate requiring DMARC on all federal email domains.

Healthcare providers ranked second-worst at 3.43.

“85 out of the 438 domains we scanned had zero protections in place (19%) — the second highest of all sectors.” continues the report. “Four domains scored full points. Three of these were part of the UK’s NHS (NHS Blood and TransplantManchester University NHS Foundation Trust, and University Hospitals Birmingham NHS Foundation Trust), and one was the Dutch cancer specialist, Prinses Máxima Centrum.”

Chinese healthcare provider domains averaged 2.1, with 45 percent fully unprotected. The Netherlands was the outlier in healthcare, averaging 6.0 with zero unprotected domains — and four domains there scored perfect marks, including three NHS trusts in the UK and a Dutch cancer center.

Universities showed an interesting failure mode. Nearly 86 percent had a DMARC record in place, which sounds good. But 42 percent of those had left DMARC in monitoring-only mode, which means phishing emails pass straight through without being blocked or quarantined. Setting up DMARC and never enforcing it is roughly equivalent to installing a lock and leaving the key in it.

Technology companies led the field with an average score of 4.83, and only 2 percent of their domains had zero protection. Only two domains in the entire study scored perfect 8/8 across all sectors: microsoft.com and f5.com. On the country side,

“Asian countries/territories had the lowest average scores, with China (2.3), South Korea (2.84), Hong Kong (3.07), and Japan (3.53) ranking among the lowest. The European countries of France (3.77), Germany (3.8), and Spain (3.98) also scored poorly.” states Comparitech.”Among the highest-scoring countries were the Netherlands (5.51), Denmark (5.33), Norway (5.31), and Finland (5.19).”

The Nordic pattern isn’t accidental: GDPR creates pressure toward stronger data protection practices, and it shows in the scores.

MTA-STS, the protocol that enforces encrypted connections for email transfer, is almost universally ignored. Only 3 percent of all domains in the study had it in place. SPF was present on 90 percent of domains and DMARC on 81 percent, but having a record in place and enforcing it are different things: a DMARC policy set to p=none does nothing to stop a phishing email from landing in someone’s inbox.

“Our report highlights how each and every industry and country has room for improvement when it comes to email security. This is even the case within sectors and/or countries where email security is regulated to some degree.” concludes the report.

“Equally, certain sectors within specific countries face heavier regulation. For example, in the US, the Department of Homeland Security (DHS) mandates that DMARC should be in use on all government agency email domains. And, in the UK, the Government Digital Service (GDS) requires DMARC across governmental domains, and with p=reject (hard fail)”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Email Security)

❌