One of the users of the Apple ecosystem has sued the tech giant. The reason is a vulnerability in the Hide My Email feature, which, contrary to stated promises, allows attackers to reveal the sender's real email address. The plaintiff claims that the company is misleading customers about the level of protection for their privacy.

A Long History of Inaction

According to 404 Media, Apple's management has been aware of the problem for over a year but has failed to take effective measures to fix it. The conflict with security researcher Tyler Murphy began back in June 2025. That was when he warned the corporation about a bug that allowed bypassing alias protection and discovering users' real addresses.

The company's reaction was formal: a month later, Apple reported the start of an investigation. However, the following months passed in waiting. In March 2026, the company notified Murphy that the issue had supposedly been resolved during system changes. But the researcher's verification showed the opposite — the vulnerability remained.

Ignoring Warnings

After a second notification, Apple again stated that the investigation was ongoing. In May, the company asked the researcher not to disclose the information publicly, assuring him that specialists were working on the issue. Murphy proposed a radical solution — temporarily suspend the function until the bug was fixed, but the proposal was ignored.

At the end of May, Apple promised to fix the situation with the release of a security update "in the coming weeks." However, at the moment, the vulnerability, which threatens protection against spam and data leaks, remains relevant.

Class Action Lawsuit

Plaintiff Anthony Alvarez emphasizes the cynicism of the situation in his statement: "Apple knew about the problem for more than a year, and this flaw has still not been fixed — all while Apple continues to profit from the 'Hide My Email' feature and its privacy promises".

Alvarez has asked the court to certify the lawsuit as a class action to protect the interests of all users whose data may have been compromised. In addition to financial compensation, the amount of which will be determined during the proceedings, the plaintiff demands that Apple be ordered to either fix the vulnerability or honestly warn users about its limitations.