苹果在 404 Media 报道后修复了“隐藏邮件”功能漏洞
Apple Fixes Hide My Email Vulnerability After 404 Media Coverage

原始链接: https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/

苹果公司修复了其“隐藏邮件地址”功能中一个长期存在的漏洞,该漏洞曾导致第三方能够获取用户的私人邮箱地址。尽管研究人员泰勒·墨菲(Tyler Murphy)在一年前就向苹果公司报告了该缺陷,但直到媒体报道和集体诉讼发生后,苹果才于 2024 年 7 月 3 日部署了修复程序。 该漏洞允许发送者在发送至掩码别名的邮件被标记为垃圾邮件并被拒绝时,获取用户的真实邮箱地址。由于此过程是自动发生的,许多用户可能并未察觉自己的数据已泄露。专家警告称,即使现在已完成修复,更新前使用的地址可能仍保留在第三方的电子邮件日志中,使用户面临持续被追踪的风险。 这项功能属于 iCloud+ 付费订阅服务的一部分,旨在通过掩盖个人联系信息来保护用户隐私。针对此次泄露事件,目前已有集体诉讼寻求为那些支付了费用却未能获得承诺隐私保护服务的客户索赔。

苹果公司修复了其“隐藏邮件地址”服务中的一个漏洞,该漏洞曾导致用户的真实电子邮件地址意外泄露给第三方。 当发送到“隐藏邮件地址”的邮件被收件人的邮件服务器作为垃圾邮件拦截时,问题便会出现。当这些邮件被退回时,自动生成的退信通知(通常会记录在发送方的邮件日志中)包含了用户真实的私人电子邮件地址。安全研究人员指出,由于这类退信往往是在静默状态下发生的,用户可能根本不知道自己的数据已经被泄露。 尽管苹果公司声称已在七月初部署了修复程序,但研究人员警告称,在补丁发布前创建的地址仍存在风险,因为泄露的数据可能仍保留在第三方服务器的日志中。 Hacker News 上的讨论也强调了人们对基于电子邮件身份识别的更广泛担忧。开发人员指出,将电子邮件地址作为账户主键的做法正变得日益成问题,特别是在“隐藏邮件地址”或自定义域名等服务使得电子邮件映射可靠性降低的情况下。批评人士认为,此次事件凸显了苹果以隐私为核心的品牌形象并不能完全避免损害用户匿名性的技术疏漏。
相关文章

原文

Apple says it has fixed a vulnerability in its Hide My Email feature which let essentially anyone figure out a user’s real email address which was supposed to be protected by the feature. Apple only fixed the vulnerability after 404 Media wrote about it at the start of July, despite Apple knowing about the issue for more than a year.

The news also follows the filing of a class action lawsuit against Apple over the vulnerability.

On Wednesday Apple told 404 Media it deployed a patch for the issue on July 3, which the company says has fully resolved the issue. 

Hide My Email is part of Apple’s paid iCloud+ product. It lets customers quickly create a new, anonymous email address they can then use to sign up to websites, services, or email people with. The generated email addresses typically contain two random words followed by a number and the @icloud.com domain. I use it heavily so hackers may have a harder time cross-referencing my activity and accounts across data breaches, for example. 

💡

Do you know about any other privacy issues like this? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at [email protected].

Tyler Murphy, co-founder of EasyOptOuts, discovered he was able to find the real email address of Hide My Email users. At the time, Murphy said, “We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.” That included mine, which we tested.

Murphy first reported the issue to Apple in June 2025. Over the subsequent months, Apple said it was looking into the issue and said it had fixed it; Murphy found it was still exploitable; and Apple again said it was looking into it. Murphy, thinking Apple may not fix the issue at all, then contacted 404 Media, around a year after Apple learned of the vulnerability.

When 404 Media first covered the issue several weeks ago, we did not include any details on how it worked because Apple had not fixed it. Meaning, if we published more specifics, third parties might figure out how to exploit it and reveal peoples’ real email addresses.

Now Apple says it has been fixed, we can add that, in simple terms, it required sending a target Hide My Email user a message that got rejected as spam. “We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected,” Murphy and EasyOptOut co-founder Ben Weiner said in a new statement.

“The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. However, we don't think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs,” they added.

The class action lawsuit against Apple seeks full recovery of the subscription costs customers paid for the feature and an injunction against Apple for its “deceptive conduct,” PCMag reported.

联系我们 contact @ memedata.com