HeadlinesBriefing favicon HeadlinesBriefing.com

Fake Hide My Email header exposes Apple Account

AppleInsider •
×

A forged Hide My Email header can trick Mac Mail into exposing a user's Apple Account address, a privacy risk extending beyond Hide My Email users. Developer Jeff Johnson discovered that a specially crafted email could cause Mail to display a misleading sender identity, while a reply would be sent from the email address tied to the user's Apple Account. This behavior did not require the use of Hide My Email or an iCloud.com mailbox.

The malicious message could arrive through an unrelated personal or business account, with Mail subsequently exposing the Apple Account address during a reply. Johnson used the `curl` command-line tool to send himself an email with an arbitrary X-Icloud-Hme header, which Mail then processed as if it originated from Apple's service. This allowed him to manipulate the sender identity shown in the reply window.

Johnson's report documents a separate technique from a previous flaw that could reveal the address behind a Hide My Email alias. The findings suggest Mail accepted sender-supplied header information without verifying its origin from Apple's Hide My Email service. While the exact macOS versions affected and whether this impacts iOS or iPadOS Mail are unclear, users are advised to inspect headers or compose new messages instead of replying directly to suspicious emails.