404 Media43%

Apple Fixes Hide My Email Vulnerability After 404 Media Coverage 56%

By Joseph Cox56%

7/21/2026, 3:20:10 PM

BS Summary: This article contains 21 faulty reasoning types, including Pessimism Bias, Ambiguity (Equivocation), and Burden of Proof, with Negativity Bias as the most egregious example at 23.3% saturation with 140 hits. Analysis detected 1,016 faulty-reasoning hits from 601 analyzed words, generating a BS Score of 54% and a BS Rank of 56% (8,643 of 19,441 articles). This article is worse (more manipulative) than 55.50% of the article peer group.

Apple says it has fixed a vulnerability in its Hide My Email feature which let essentially anyone figure out a user’s real email address which was supposed to be protected by the feature. 
Apple only fixed the vulnerability after 404 Media wrote about it at the start of July, despite Apple knowing about the issue for more than a year. 
The news also follows the filing of a class action lawsuit against Apple over the vulnerability. 
On Wednesday Apple told 404 Media it deployed a patch for the issue on July 3, which the company says has fully resolved the issue. 
Hide My Email is part of Apple’s paid iCloud+ product. 
It lets customers quickly create a new, anonymous email address they can then use to sign up to websites, services, or email people with. 
The generated email addresses typically contain two random words followed by a number and the @icloud.com domain. 
I use it heavily so hackers may have a harder time cross-referencing my activity and accounts across data breaches, for example. 
💡 Do you know about any other privacy issues like this? 
I would love to hear from you. 
Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co. 
Tyler Murphy, co-founder of EasyOptOuts, discovered he was able to find the real email address of Hide My Email users. 
At the time, Murphy said, “We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.” 
That included mine, which we tested. 
Murphy first reported the issue to Apple in June 2025. 
Over the subsequent months, Apple said it was looking into the issue and said it had fixed it; Murphy found it was still exploitable; and Apple again said it was looking into it. 
Murphy, thinking Apple may not fix the issue at all, then contacted 404 Media, around a year after Apple learned of the vulnerability. 
When 404 Media first covered the issue several weeks ago, we did not include any details on how it worked because Apple had not fixed it. 
Meaning, if we published more specifics, third parties might figure out how to exploit it and reveal peoples’ real email addresses. 
Now Apple says it has been fixed, we can add that, in simple terms, it required sending a target Hide My Email user a message that got rejected as spam. 
“We don't know how often hidden email addresses were leaked in email logs. 
For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. 
Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected,” Murphy and EasyOptOut co-founder Ben Weiner said in a new statement. 
“The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. 
However, we don't think the risk to Hide My Email users has been eliminated. 
Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs,” they added. 
The class action lawsuit against Apple seeks full recovery of the subscription costs customers paid for the feature and an injunction against Apple for its “deceptive conduct,” PCMag reported. 
Confirmation Bias
11%
Anchoring Bias
8.3%
Availability Heuristic
3.3%
Representativeness Heuristic
0%
Hindsight Bias
4.5%
Overconfidence Bias
9%
Framing Effect
5%
Loss Aversion
0%
Status Quo Bias
4%
Sunk Cost Effect
0%
Optimism Bias
0%
Pessimism Bias
20%
Negativity Bias
23.3%
Self-Serving Bias
3.5%
Fundamental Attribution Error
0%
Actor-Observer Bias
0%
In-Group Bias
0%
Out-Group Homogeneity Bias
0%
Halo Effect
0%
Horn Effect
0%
Dunning-Kruger Effect
0%
Recency Bias
5.5%
Primacy Effect
0%
Blind-Spot Bias
0%
Ad Hominem
0%
Straw Man
0%
Appeal to Authority
0%
False Dilemma
0%
Slippery Slope
0%
Circular Reasoning
0%
Hasty Generalization
9%
Red Herring
0%
Bandwagon
4.8%
Appeal to Emotion
1.8%
Begging the Question
0%
Post Hoc (False Cause)
4.5%
Tu Quoque
0%
Burden of Proof
17.8%
Appeal to Nature
0%
Composition/Division
0%
Anecdotal
4.5%
No True Scotsman
0%
Ambiguity (Equivocation)
20%
Gambler’s Fallacy
0%
Middle Ground
0%
Personal Incredulity
0%
Special Pleading
0%
Genetic Fallacy
0%
Unattributed Quote
4.2%
Quote-first Misdirection
0%
Biased Writer Voice
0%
Indoctrination
1.8%
Politically Left Leaning Bias
0%
Politically Right Leaning Bias
0%
Attempt to Sell a Product or Service
3.3%

601 words analyzed.

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.