Header Banner
Gadget Hacks Logo
Gadget Hacks
Apple
gadgethacks.mark.png
Gadget Hacks Shop Apple Guides Android Guides iPhone Guides Mac Guides Pixel Guides Samsung Guides Tweaks & Hacks Privacy & Security Productivity Hacks Movies & TV Smartphone Gaming Music & Audio Travel Tips Videography Tips Chat Apps
Home
Apple

Fake Hide My Email Header Flaw Leaks Apple Account Address

Fake Hide My Email header flaw leaks Apple Account address

A forged email header can trick Mac Mail into sending your reply from your Apple Account address without warning, and you don't need to use Hide My Email, or even have an iCloud.com mailbox, for it to happen. Developer Jeff Johnson disclosed the technique two days ago: by embedding a crafted X-Icloud-Hme header in an incoming message, a sender can cause Mail to misroute your reply through your Apple Account identity while the compose window displays something else entirely, AppleInsider reported today.

Johnson doesn't use Hide My Email. He has no iCloud.com address. His Apple Account was still exposed. French outlet MacGeneration independently reproduced the behavior and confirmed the same outcome for non-iCloud users. Apple has issued no patch, no public statement, and no advisory.

How the forged X-Icloud-Hme header triggers Apple Account email address exposure

The core problem is a gap between what Mail displays before you send and what it actually transmits.

Johnson used curl, a standard command-line tool, to send himself a message containing an arbitrary X-Icloud-Hme header, the internal field Mail uses to recognize messages legitimately relayed through Apple's Hide My Email service. He chose the header's value himself. The manipulation happens entirely on the sender's side before the email arrives; ordinary Mail users have no equivalent control over incoming metadata, AppleInsider reported today.

Mail responded by displaying "Hide My Email" in the reply window's From field and adding a notice claiming the original message had been forwarded through Apple's alias service, both false. When Johnson sent the reply, it went from his Apple Account address. Nothing in the compose window flagged it beforehand.

The result suggests Mail accepted information supplied by the sender without first establishing that Apple's Hide My Email service had generated it, AppleInsider reported today. Johnson's report documents visible behavior and doesn't identify the app's internal validation process, so the precise mechanism remains unconfirmed. The observable outcome, though, is unambiguous: the compose window showed one identity while Mail sent from another, giving Johnson no accurate warning that his Apple Account address would be exposed.

Think of it as inbound spoofing with a delayed trigger. The sender builds the trap inside the incoming message; the victim springs it by hitting Reply.

Fake Hide My Email header: who can be affected

This isn't a Hide My Email subscriber problem.

The flaw can affect any Mac Mail user with an Apple Account configured in the app. Johnson proved it against himself: no Hide My Email subscription, no iCloud.com mailbox, yet his Apple Account address was exposed in the reply, per AppleInsider. The crafted message doesn't need to arrive in an iCloud inbox either. Johnson found it can land in a separate Gmail or work account, and Mail may still route the reply from the Apple Account address rather than the account that actually received the email. Mail manages multiple accounts simultaneously; users reasonably expect those identities to stay separate, and this behavior suggests that boundary can be crossed without any warning at send time.

That makes the stakes highest for people who deliberately keep their Apple Account address out of professional or sensitive correspondence: journalists, researchers, legal professionals, activists, anyone managing distinct identities inside a single Mail app.

One caveat worth stating plainly. Johnson's disclosure doesn't identify which macOS versions are affected, doesn't confirm whether Mail on iPhone or iPad replicates the behavior, and presents no evidence the technique has been used in any real-world attack, AppleInsider noted today. The documented risk is a reproducible privacy exposure, not evidence of active exploitation.

What to do right now

No patch exists. The available protection is a change in how you reply.

  • The signal to watch for: if a reply window unexpectedly labels the From address as "Hide My Email," particularly when the original message didn't arrive through a Hide My Email alias you recognize, close the compose window without sending. That unexpected label is the clearest indicator the incoming message may carry a forged header, per AppleInsider.
  • The workaround: compose a new message, manually select the From address, and confirm it before sending. This sidesteps the reply-routing behavior Johnson documented entirely. It doesn't fix anything in Mail, but it restores identity verification to your control. In Johnson's test, the exposure occurred only after he sent the reply, so composing fresh stops the mechanism before it fires.
  • For the extra cautious: Mac Mail can display a message's full raw headers via View → Message → All Headers, a command Johnson noted can be added to the message toolbar. An X-Icloud-Hme header present in a message that arrived through a non-iCloud account warrants a closer look. The header alone doesn't establish who added it or why, but combined with an unexpected "Hide My Email" label in the reply window, it should be treated as a stop sign, per AppleInsider.

A separate flaw, a year without a fix, and a lawsuit

Johnson's disclosure is technically distinct from an older Hide My Email vulnerability. He has said he doesn't know whether the two share any underlying cause. But both belong in the same paragraph of Apple's recent privacy record, because both produced the same kind of failure: Apple-branded privacy infrastructure behaving in ways that contradict what the interface tells the user.

That earlier flaw was reported to Apple in June 2025 by Tyler Murphy of EasyOptOuts. It allows the real address behind a Hide My Email alias to be revealed without special access or technical privileges. In limited volunteer testing, every Hide My Email address tested was exploitable, 9to5Mac reported three weeks ago. 404 Media independently verified the issue against its own hidden address while withholding exploit details. Apple told Murphy the problem was resolved in March 2026. It was not.

Apple then asked Murphy to stay quiet until a fix was ready, promised a resolution by June, and delivered neither, so he went public, 9to5Mac reported. A proposed class action filed July 15 alleges Apple continued selling Hide My Email as a core iCloud+ feature while the alias-reveal vulnerability remained unpatched, ClassAction.org reported four days ago. The complaint doesn't allege any plaintiff's address was exposed in an actual attack.

What connects both issues isn't their technical architecture. As knutmichael.com framed it earlier this month, a privacy alias is a security boundary, and that boundary depends on the alias-to-account mapping staying unobservable across every system path: delivery, replies, bounces, and beyond. When it surfaces unexpectedly through any of those paths, the feature fails regardless of what the interface claims.

What remains unknown

Which macOS versions trigger the behavior, whether it appears in Mail on iPhone or iPad, and how Apple intends to respond are all open questions. The compose window showed Johnson one identity and sent another. Until Apple addresses that, users who keep their Apple Account address private have one reliable option: skip the Reply button, compose a fresh message, and check the From field before hitting Send.

Apple's iOS 26 and iPadOS 26 updates are packed with new features, and you can try them before almost everyone else. First, check our list of supported iPhone and iPad models, then follow our step-by-step guide to install the iOS/iPadOS 26 beta — no paid developer account required.

Sponsored

Related Articles

Comments

No Comments Exist

Be the first, drop a comment!