Apple’s Hide My Email feature was intended to safeguard users’ personal inboxes. However, a recent lawsuit raises concerns that this privacy tool may not provide the level of protection it advertises.

In California, a proposed class action lawsuit claims that Apple has misled customers about a potential flaw that could expose the real email addresses associated with Hide My Email aliases. The complaint alleges that Apple was aware of this issue for over a year yet continued to promote the feature through Sign in with Apple and iCloud+.

As of the time of this report, Apple had not issued a public response regarding the lawsuit.

Lawsuit Challenges Apple’s Privacy Promises

California resident Anthony Alvarez has filed the suit on behalf of himself and other Apple users who have utilized the Hide My Email feature. The complaint states, “The flaw remains unfixed to this day, all while Apple continues to profit from Hide My Email and from its promises of privacy,” as reported by 9to5Mac.

According to MacRumors, a security researcher allegedly brought this flaw to Apple’s attention in June 2025. While Apple purportedly indicated that it had resolved the issue by March 2026, the researcher claims it was still exploitable. No confirmed instances of exploitation have been reported, and detailed technical information has yet to be made public.

The complaint also seeks certification of nationwide and California groups representing Apple customers and iCloud+ subscribers, with claims potentially exceeding $5 million, as noted by The Mac Observer.

Understanding How Hide My Email is Designed to Work

The Hide My Email feature creates unique email addresses that forward messages to a user’s actual inbox. This setup ensures that websites, apps, and newsletters see only the alias, not the personal email address behind it.

Apple offers a basic version through Sign in with Apple, while a more extensive option is available for iCloud+ subscribers starting at $0.99 per month, enabling users to create additional aliases for their online interactions. This feature helps diminish spam and restrict how many companies can access an individual’s primary email address. However, it is crucial to note that it does not encrypt messages or anonymize the user.

Essential Apple Coverage

Potential Risks for Hide My Email Users

An email address can reveal more than just its intended use for message reception. Companies frequently leverage email addresses as account identifiers, while data brokers and attackers may use them to associate activities across different platforms.

If the alleged flaw allows a Hide My Email alias to be traced back to a user’s real address, it could expose them to increased phishing attacks, profiling, spam, or account recovery issues. The risk intensifies for users whose exposed addresses are part of leaked databases containing personal information such as names, phone numbers, and passwords.

Organizations that permit staff to utilize personal Apple IDs or Hide My Email aliases for professional services should assess the appropriateness of these aliases for account recovery or identity verification. Furthermore, security teams should consider aliases as an additional privacy layer rather than a comprehensive identity protection tool, particularly when an exposed address may correlate with information from earlier data breaches.

While the lawsuit has yet to prove that Apple violated the law or that any breaches exposed users’ addresses, its outcome may influence how technology companies present privacy tools and clarify their limitations. The court is still deliberating whether this lawsuit will proceed as a class action, and Apple has not publicly commented on the matter. Until more technical details emerge, users should view email aliases as a valuable privacy tool, but not as an infallible safeguard against linking their true identity to their underlying addresses.

For further insights, explore our detailed coverage of Apple’s security updates for 2026, highlighting zero-days, iPhone exploit kits, WebKit improvements, and essential patches for users and IT departments to monitor.

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts