News
- Apple Hide My Email can reveal a user's authentic email address
- The bug puts users at risk of identification, experts warned
- It has been unpatched for over a year
A bug in Apple’s ‘Hide My Email’ feature allows for those with knowledge of the vulnerability to identify the real email address hidden behind the anonymous email address.
The bug was discovered by EasyOptOuts co-founder, Tyler Murphy, who shared the exploit with 404 Media after notifying Apple multiple times that the feature could be actively exploited.
“We reported the issue and replication instructions to Apple over a year ago. We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer,” Murphy said.
Hide My Email can be actively exploitedAs the bug still hasn’t been patched, the details of how the exploit works have not been shared.
Apple’s Hide My Email feature was designed to anonymize email addresses, helping to prevent a user’s real email address from being leaked in a data breach, or to prevent a user’s email address from being linked to them personally in a way that could reveal their identity.
There lies the crux of the issue. By being able to identify the real email address by exploiting the bug, a malicious actor could uncover the real identity of the anonymized email.
“Free, publicly accessible people-search sites make it easy to link an email address to other personal details, so people relying on Hide My Email for safety may be at risk,” Murphy said. “We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.”
Users concerned about being identified via people-search sites can use a data removal service to have their data scrubbed from these sites, but the process can take a few days.
The issue was first reported to Apply by Murphy in June 2025, with Apple replying a month later that it was looking into the cause of the issue. Earlier this year, in March, Apple said that it had “addressed the reported issue in a recent system change,” but Murphy found that the bug could still be exploited.
Again, Murphy notified Apple, who replied in May 2026, stating, “We are still investigating this issue. To avoid placing our customers at risk, we would appreciate you not disclosing this information until our investigation is complete. We appreciate your assistance in helping us to maintain and improve the security of our products."
Later in the same month, Apply said a fix was “expected in the coming weeks."
Regulated industries are entering a turning point that many enterprise leaders have yet to fully grasp.
Agentic AI tools capable of executing multi-step tasks with minimal human intervention, are now commonly embedded in audit and finance operations, automating testing, documentation, risk assessment, and reporting.
But many organizations are still behind updating the governance infrastructure required to make those gains sustainable.
Most organizations ask what AI can do, but neglect to evaluate whether they have operating models, governance frameworks, and human oversight capacity in place to control what AI does.
In regulated environments, that gap is where exposure compounds quickly.
Three Gaps Compounding at OnceValidating AI output requires a different skill set than producing it. Traditional audit training doesn’t develop that capability, and most firms have yet to redesign programs to account for that lack of knowledge.
Junior staff are nominally in charge of reviewing AI-generated work they don’t fully understand. In regulated environments, this creates easy-to-miss opportunities for exposure.
Audit workflows were designed around human pacing and judgment. Agentic AI moves sequentially and at speed, silently resolving ambiguity rather than surfacing it.
Layering AI tools onto processes built for human practitioners means unclear handoffs, undefined escalation paths, and audit trails that fail to document decision rationale in ways that satisfy regulators.
When stewardship is a title rather than a function, organizations produce governance documentation that exists on paper, not in practice.
Premature AI deployment can still look like a success even long after the foundation started to erode. Adoption metrics show usage. Cycle times improve.
These ostensibly positive outcomes don’t reveal whether employees can meaningfully evaluate what the system produces, whether workflows have been redesigned for how AI operates, or whether governance is anywhere close to complete.
For enterprise leaders in regulated industries, the critical question is not whether the AI is working, but whether it surfaces issues early enough for teams to intervene effectively.
In many organizations, AI implementation is also outpacing operational alignment. Risk, compliance, finance, and technology teams often operate with different assumptions about how agentic systems are being used and where accountability resides.
Without shared oversight across those functions, governance gaps become harder to identify before they create operational or regulatory consequences.
What Closing the Gap Actually Looks LikeThe organizations seeing sustainable results share a key characteristic: they build governance infrastructure before scaling use cases. In practice, that means establishing a centralized governance function with both business and technical representation.
Successful AI governance in regulated environments requires joining stakeholders who understand operational stakes and regulatory requirements at the same table, with the authority to act on what they find.
Domain stewards need real authority, with clear accountability for model performance, explicit escalation paths, and organizational backing to act accordingly. Defined rules of engagement are what separates a stewardship role from a title implying nominal ownership on an org chart. This structure must be built before deployment, not retrofitted after an incident.
Starting narrow is the right instinct. Financial close, reconciliations, and anomaly detection are good initial use cases due to clean inputs, measurable outputs, and the presence of a human reviewer that evaluates what the system produced.
Data flows need to be integrated across systems before models go into production. Scaling AI into fragmented processes doesn’t fix fragmentation—it accelerates it. Selecting a technology capable of bringing data integrity to the forefront is key for establishing sustained governance practices.
Workforce readiness belongs on the governance roadmap alongside technical deployment. Junior staff need structured development in how to evaluate AI output including when to trust it, when to push back, and when to escalate. That capability doesn’t emerge simply from exposure to AI tools. The firms getting this right are treating this part of the process as risk control.
Another challenge is that many governance models remain reactive rather than adaptive. Regulatory expectations surrounding AI are evolving faster than most enterprise oversight structures, leaving organizations vulnerable to compliance gaps that may not become visible until after deployment.
Companies that treat governance as an ongoing operational discipline, rather than a one-time implementation exercise, will be better positioned as both technology capabilities and regulatory scrutiny continue to advance.
Governance Is the FoundationAgentic AI will continue expanding into audit and finance regardless of whether governance infrastructure is in place. The competitive pressure is too strong, and the case for efficiency is too compelling for adoption to slow.
The question for enterprise leaders isn’t whether to deploy AI—it's whether they’re building the operational foundation to deploy it responsibly.
Accountability in regulated industries does not transfer to the algorithm. It stays with the humans who chose to deploy it, and with the organizations that decided they were ready when the evidence said otherwise.
The leaders who are prepared have already answered this question: if something goes wrong, do we know exactly where judgment ended and automation began?
Manage employees with the best HR software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
- Microsoft posted an ad promoting Copilot on social media
- It said that Copilot is the "button you can press to fix everything"
- This has elicited quite the outpouring of rage from some folks, and it's not a wise promo given the prevailing climate around AI and Windows 11
Microsoft is catching some flak once again over the topic of AI in Windows 11, following what might be regarded as an overzealous piece of marketing.
Windows Latest noticed that Microsoft's marketing department posted an image across its social media (Facebook, Instagram, and X) which promoted the dedicated Copilot button and the AI assistant it summons.
The text featured in the pic was: "Them: There's no button you can press to fix everything," followed by a reply as if in a conversation that read: "Me: Wanna bet?"
Predictably this has stirred up some controversy, with responses to Microsoft's little ad that range from accusing Copilot of being "AI slop" (or "Microslop") through to comments along the lines of "no one wants this" and similar negativity.
(Image credit: Windows Latest / Microsoft)Undermining the fix Windows 11 effortThis is a particularly poorly timed piece of PR, given that, as Windows Latest observes, Microsoft is finally bringing in the ability to change the Copilot key back to function as Right Control. This is the key that the Copilot button replaced on 'AI PCs' (laptops), but as some people have said, Right Control is crucial to their workflow (and has accessibility ramifications for one-handed keyboard use).
With that change coming to Windows 11 later this year — an effective softening of Microsoft's initial stance that you should have the Copilot key and like it — this marketing snippet feels even more badly judged.
What's worse here for me is the exaggeration of the usefulness of the Copilot key. The AI can "fix everything" can it? It's a frankly ridiculous statement to make, and yes, I know that's not exactly uncommon in advertising, but you've got to bear in mind your target audience here and the context.
AI in Windows 11 has triggered a lot of bad feeling in the user base since last year, and indeed Microsoft's blinkered focus on pushing AI was one of the reasons that people were up in arms about fixing the OS rather than adding Copilot trimmings. Or in other words, the big fix Windows 11 campaign — which is the focus of this entire year for Microsoft — was partly the result of all the anti-AI feeling.
So, erm, let's market around the Copilot key being this amazing solve-all feature, shall we? Sounds like a great plan, everyone. Full steam ahead! Let's talk about how great it would be to add more AI into Notepad while we're at it, yeah? (Apologies, I remapped my Copilot key to be a 'Sarcasm' key and it appears to be jammed down right now).
Microsoft also says the Copilot key is a button with "main character energy" in this advert, the problem being that if AI in Windows 11 was a movie, it's been a box office turkey for the software giant so far. Microsoft's hope is that AI agents in Windows 11 will turn things around, but it remains to be seen how that'll pan out.
Meantime, while Microsoft is trying to generate positivity and good vibes around Windows 11 with all its (very commendable) work to fix the OS, it'd be better for the software engineers and designers in the thick of it not to have those efforts undermined by the marketing crew wheeling out unintentional ragebait like this Copilot button nonsense.
Now, I'm not saying that Microsoft's PR team can never mention AI, of course, but this particular snippet on social media is a perfect example of how not to do it in the current Windows 11 climate.


