Remix.run Logo
lapcat 4 hours ago

> Apple told 404 Media it deployed a patch for the issue on July 3, which the company says has fully resolved the issue.

> Now Apple says it has been fixed, we can add that, in simple terms, it required sending a target Hide My Email user a message that got rejected as spam.

I would note that Mac Mail app (I haven't tested iOS Mail) still has an Apple Account email address disclosure vulnerability, though this requires the user to reply to a maliciously crafted email. The vulnerability affects all users of Mail app, even if they don't use Hide My Email! https://lapcatsoftware.com/articles/2026/7/9.html

philipwhiuk 2 hours ago | parent [-]

> The vulnerability affects all users of Mail app, even if they don't use Hide My Email!

If they don't use "Hide My Email" trivially replying discloses their email?

layer8 2 hours ago | parent | next [-]

It will disclose your Apple account address even when you received the email on a different account in the Mail app.

2 hours ago | parent | prev [-]
[deleted]