Dettaglio notizia
| Data | 03/07/2026 |
| Titolo | Apple Hide My Email Flaw Exposes Users’ Real Email Addresses |
| Contesto | A reported vulnerability in Apple’s iCloud+ Hide My Email service allows an attacker with only a relay alias to uncover the user’s real email address, defeating a privacy feature widely used to mask identity. Researcher Tyler Murphy of EasyOptOuts said he disclosed the issue to Apple in June 2025, and multiple outlets reported that 404 Media independently verified the flaw by recovering a reporter’s actual Apple ID email from a newly created alias. Public reporting says the issue requires no account compromise, special access, or social engineering, raising risks of phishing, spam correlation, account linkage, and exposure of personal details through people-search services. Apple reportedly acknowledged the bug in 2025 and later told Murphy that a system change had addressed it, but follow-up testing found the deanonymization still worked more than a year after disclosure. Murphy said volunteer testing showed all tested aliases were reversible, though the full scope across the user base remains unclear, and exact exploitation details were withheld while Apple continued investigating. As of the reports, Apple had not issued a public advisory or CVE, and separate coverage noted that Apple’s planned migration of masked addresses to the @private.icloud.com domain could make Hide My Email aliases easier for websites and apps to identify and block. |
| Fonte | https://mallory.ai/stories/019f1e04-8ca0-7064-aa71-1f2a3c97e955 |
| Discussione? | Parliamone sul Forum |