A vulnerability in Apple’s iCloud Plus “Hide My Email” feature may allow attackers to connect a user’s anonymous email address with their real one, potentially compromising privacy. The issue affects users of the privacy-focused service.
A report indicates that the vulnerability exists within the way Apple handles email forwarding rules. According to CNET, this flaw could enable an attacker to discover the genuine email addresses associated with users who utilize “Hide My Email.” This feature is designed to mask a user’s real email address when signing up for online services.
Engadget reported that the vulnerability can reportedly connect real email addresses to anonymous ones. The process involves sending an email to the masked address, which then triggers a forwarding response revealing the original email. While Apple intended for this feature to enhance privacy by preventing direct sharing of personal email addresses, the current implementation appears to have created a loophole.
The “Hide My Email” function is part of Apple’s iCloud Plus subscription service, offering features like Private Relay and increased iCloud storage. Users can generate unique, random email addresses that forward messages to their real inbox. The intention is to shield personal email addresses from spam and tracking.
No right-leaning sources reported on this story.
Read the original coverage
💬 Comments
📜 Comment Policy