A fake Hide My Email header can expose the address behind your Apple Account
AI-summarised brief · reviewed before publication
Apple Mail’s privacy flaw, revealed by developer Jeff Johnson on July 19, allows a forged Hide My Email header to expose a user’s Apple Account address. Johnson’s test showed that a crafted message could mislead the sender field while a reply was sent from the Apple Account’s real email address. The exploit works without using Hide My Email or an iCloud.com mailbox, and can be triggered by a message from any personal or business account. Johnson’s report distinguishes this technique from a prior alias‑reveal bug, indicating a separate vulnerability.
💡 Why It Matters
- · The flaw undermines Apple’s core promise of email anonymity, potentially exposing users to targeted phishing or identity theft.
- · It forces Apple to address a critical privacy gap that could erode trust in its ecosystem.