Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AT&T tops targets for wireless subscriber additions as bundle offers gain traction

    US war in Iran has cost US$37.5 billion so far: Pentagon

    Bank Indonesia keeps rates unchanged, offers incentives to attract inflows

    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest VKontakte
    Sg Latest NewsSg Latest News
    • Home
    • Politics
    • Business
    • Technology
    • Entertainment
    • Health
    • Sports
    Sg Latest NewsSg Latest News
    Home»Technology»Fake Hide My Email header can expose your Apple Account
    Technology

    Fake Hide My Email header can expose your Apple Account

    AdminBy AdminNo Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A forged Hide My Email header can make Mac Mail expose a user’s Apple Account address, extending the privacy risk beyond people who use Apple’s alias service.

    Developer Jeff Johnson disclosed the Mac Mail privacy flaw on July 19. His testing showed that a specially crafted message could make Mail display a misleading sender identity while a reply went out from the email address tied to his Apple Account.

    The behavior didn’t require Johnson to use Hide My Email or maintain an iCloud.com mailbox. He also found that the malicious message could arrive through an unrelated personal or business account before Mail exposed the Apple Account address in a reply.

    Johnson said he doesn’t know whether the finding is technically related to an earlier flaw that could reveal the address behind a Hide My Email alias. His report documents a separate technique and doesn’t establish that both issues share the same underlying cause.

    Johnson used the curl command-line tool to send himself an email containing an arbitrary X-Icloud-Hme header. Mail doesn’t give users direct control over arbitrary outgoing headers, while curl allowed him to choose the values placed inside it.

    By controlling those values, Johnson could make Mail show selected addresses in the reply window. The app also displayed “Hide My Email” in the From field and added a notice saying the message had been forwarded through the service.

    The result suggests Mail accepted information supplied by the sender without first establishing that Apple’s Hide My Email service had generated it. Johnson demonstrated the visible behavior, but his report doesn’t identify the app’s internal validation process.

    Email compose window on a Mac with To, Cc, Subject, and From fields visible; addresses and subject text are blacked out for privacy, showing use of Hide My Email featureA crafted X-Icloud-Hme header was sufficient to trigger the Mac Mail bug in Johnson’s testing. Image credit: Jeff Johnson

    The problem goes beyond a misleading label because users rely on the From field to confirm which account will send a message. Mail reportedly showed one identity while sending the reply from another, giving Johnson no accurate warning that his Apple Account address would be exposed.

    The reported flaw reaches beyond Hide My Email users

    Johnson said he doesn’t use Hide My Email and doesn’t have an iCloud.com email account. That makes the reported issue broader than a flaw limited to people actively using Apple’s alias service.

    A crafted message can also arrive through a separate email account, yet Johnson said Mail may still send the reply from the address tied to the recipient’s Apple Account. The distinction matters for people who keep personal, business and Apple Account identities inside the same Mail app.

    Apple Mail can manage multiple accounts from different providers, and users reasonably expect those identities to remain separate. Johnson’s test shows that the compose window may not always reflect the address that Mail will actually transmit.

    Johnson documented a technique he reproduced in his own testing, but the report doesn’t establish which macOS versions are affected. It also doesn’t show whether the same behavior works in Mail on iPhone or iPad, and it offers no evidence that anyone has used the technique in an attack.

    Email client window showing a single highlighted message with a blue dot and the text This message was forwarded to you by Katy Graef, plus toolbar icons and a Settings linkThe only other warning was a notice above the message saying it had been forwarded through Hide My Email. Image credit: Jeff Johnson

    Crafted email headers have caused problems for Apple Mail before. In 2022, a specially formatted From field could prevent some iOS 16 users from opening Mail, although that issue caused a crash rather than exposing an email address.

    The new finding also arrives while Apple faces legal scrutiny over the earlier Hide My Email disclosure. A proposed class action lawsuit filed July 15, accuses the company of misleading customers about the feature, although the complaint doesn’t allege that attackers exposed the plaintiff’s address or exploited the flaw.

    How to protect yourself from the Mac Mail disclosure flaw

    Mac Mail users should stop before sending when a reply window unexpectedly labels the From address as “Hide My Email,” particularly when the original message wasn’t sent to an alias. In Johnson’s test, the disclosure occurred only after he sent the reply.

    Users can inspect a received message’s complete headers by opening the View menu, selecting Message and choosing All Headers. Johnson noted that the command can also be added to the message window’s toolbar.

    The presence of an X-Icloud-Hme header doesn’t establish who added it or why. An unexpected Hide My Email label combined with unusual From or To fields should still be treated as a warning.

    MacGeneration independently reproduced the Mail bug and confirmed that it can expose an Apple Account address even when the user doesn’t use iCloud for email. The publication’s testing supports Johnson’s findings, though the affected Mail app versions remain unclear.

    Users who need to respond should create a new message and confirm the From address before sending instead of replying directly to the suspicious email. Creating a separate message won’t fix the underlying Mail bug, but it avoids the reply behavior Johnson documented.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Admin
    • Website

    Related Posts

    New Zealand online scams surge as trust is exploited

    Strange New Worlds’ Fourth Season Takes Big Swings

    Maximize Your Study Efficiency With These 15 AI Student Planners In 2026

    Substack now lets you check if a post was written by AI

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Most Impressive Team Streaks Of The 21st Century: Where Does 2024-26 Spain Rank?

    NBC’s ‘Stumble’ is a mockumentary about a cheer team with plenty of tumbling runs and heart

    Xiaomi shares post worst week in 3½ years as accidents stoke EV safety concerns

    Judge reverses Trump administration’s cuts of billions of dollars to Harvard University

    Top Reviews
    9.1

    Review: Mi 10 Mobile with Qualcomm Snapdragon 870 Mobile Platform

    By Admin
    8.9

    Comparison of Mobile Phone Providers: 4G Connectivity & Speed

    By Admin
    8.9

    Which LED Lights for Nail Salon Safe? Comparison of Major Brands

    By Admin
    Sg Latest News
    Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
    • Get In Touch
    © 2026 SglatestNews. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.