Apple sells the idea of privacy. Private Relay and Hide My Email don't come as free extras bundled with an iPhone. They come with iCloud+, the subscription people pay Apple for every month, and both have been leaking the exact information they were sold to hide.
Private Relay is meant to stop websites from seeing the address that identifies your home network. Researchers Talal Haj Bakry and Tommy Mysk published that a website can defeat it three different ways, sending the traffic straight out of the phone so it never touches the relay the subscriber pays for.
One of the three needs nothing from the user. The visitor does not click, sign in, or turn anything on. Opening the page is enough and it has worked that way in shipping iPhones since September 2024.
What leaks is the address that identifies your network - the one a site would otherwise never see - and it is enough to tie separate visits back to the same person. What you read and typed stays hidden. The researchers, who make a competing browser, put up a test page anyone can run on their own device.
Apple has said it is investigating and has not given a date.
Hide My Email is sold to hand a company a throwaway address so it never learns your real one. It was leaking the real address behind the alias. In the researchers' limited tests, every generated address could be traced back. Tyler Murphy of EasyOptOuts told 404 Media that "publicly accessible people-search sites make it easy to link an email address to other personal details, so people relying on Hide My Email for safety may be at risk."
The reach had a limit. A sender already had to hold a target's alias to unmask the address behind it.
Murphy reported it to Apple in June 2025, with instructions to reproduce it. Apple twice said it was fixed - in March 2026, then again on June 30 - and both times Murphy reproduced the leak. Apple then told 404 Media, which broke the story, that a patch on July 3, 2026 fully resolved it, thirteen months after it was first told. EasyOptOuts said the exploits it had reported were closed by July 14. AppleInsider reproduced the flaw on July 17, two weeks past Apple's date, and says Apple has not explained why the test still worked.
The damage stands even after the fix. Murphy and co-founder Ben Weiner say any alias created before July 7, 2026 may already be stored in other companies' logs, because rejected messages carried the real address and mail logs are kept for months or years.
"It's been almost a year since the issue was reported, and in that time, everyone purchasing access to Hide My Email has unknowingly been buying a product that Apple knows is faulty," Murphy and Weiner said before the patch.
Apple is being sued over it. The complaint says the company broke California's false advertising law because it knew Hide My Email did not do what it was sold as doing. Those are allegations.
Both failures happened for the same reason. Other parts of Apple's own software went around the very privacy feature Apple was charging for. Requests fired off from the phone outside Private Relay's path. Apple's own mail servers printed the hidden address into the notice that bounces back when a message is refused.
The customer has no way to check that either feature works.
So this is a consumer protection question, not only a security one. Privacy sold on a subscription is a product claim. A company that takes the money and does not deliver has done more than run late on a bug fix.
A VPN carries everything the phone sends, so it closes the Private Relay route. It does nothing for the mail-server leak, which lives on Apple's own servers, not on the phone. No product the customer installs reaches it.




