Apple、メール保護機能の脆弱性を修正
Apple は、Hide My Email の機密情報を漏洩させる脆弱性に対し、外部メディアによる報道と訴訟の圧力を受けてようやく修正パッチを適用した。
キーポイント
長期間放置された脆弱性の修正
Apple は約1年前からこの問題を知っていたが、404 Media の報道とクラスアクション訴訟の発生後、7月3日にようやくパッチを適用した。
漏洩メカニズムの特定
スパムとして拒否されたメールを送信するだけで、ユーザーの実在メールアドレスが送信者に露呈するという脆弱性が確認された。
影響範囲と検出の難しさ
多くの主要なメールホストで発生しており、受信トレイではなくスパムフォルダに届くため、ユーザー自身が被害に気づきにくい状況だった。
リスクの完全排除は不可能
不具合は修正されたものの、非悪意あるメールのバウンスやログ保存により、2026年7月7日以前に作成されたアドレスが依然として第三者のログに存在する可能性がある。
集団訴訟の請求内容
PCMagによると、ユーザーは機能への支払い分全額返還と、Apple の「欺瞞的な行為」に対する差止命令を求めて集団訴訟を起こしている。
重要な引用
Apple only fixed the vulnerability after 404 Media wrote about it at the start of July, despite Apple knowing about the issue for more than a year.
in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.
The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed.
"Because non-malicious emails could bounce, revealing your hidden email address... any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs."
"The class action lawsuit against Apple seeks full recovery of the subscription costs customers paid for the feature and an injunction against Apple for its 'deceptive conduct.'"
影響分析・編集コメントを表示
影響分析
この事件は、大手テック企業が自社のプライバシー機能を長期間放置し、外部からの批判や法的リスクに直面して初めて行動を起こすという典型的な事例を示している。ユーザーにとって、Apple のセキュリティ機能への信頼が揺らぎ、特に機密情報の保護を目的としたサービス利用において注意が必要となる。
編集コメント
プライバシー保護を謳う機能に致命的な欠陥があり、かつ長期間放置されていた事実は、企業のセキュリティガバナンスに対する重大な懸念を示しています。ユーザーは単なる機能の存在だけでなく、その実効性と企業の対応姿勢にも注視する必要があります。
Apple は、Hide My Email の機能に存在する脆弱性を修正したと発表した。この脆弱性により、本来保護されるべきユーザーの実在のメールアドレスを、事実上誰でも特定できてしまう状態になっていた。
Apple はこの問題について 1 年以上前から把握していたにもかかわらず、7 月初めに 404 Media が報じたのをきっかけにようやく修正を行った。
今回のニュースは、同様の脆弱性を巡って Apple を相手取った集団訴訟が提起されたこととも関連している。
水曜日、Apple は 404 Media に対し、7 月 3 日に本件のパッチを適用したと回答。同社はこれで問題が完全に解決されたと説明している。
Hide My Email は、有料の iCloud+ プランに含まれる機能だ。ユーザーはこれを使って、すぐに新しい匿名メールアドレスを作成し、ウェブサイトやサービスの登録、あるいは他人へのメール送信に利用できるようになる。生成されたアドレスは通常、2 つのランダムな単語に数字を付加し、@icloud.com ドメインを付けた形式となる。
私はこの機能を頻繁に利用しているが、データ侵害が発生した際にも、ハッカーが私の活動やアカウントを他と照合して特定する難易度を高めることができるためだ。
このようなプライバシーに関する他の問題をご存知ですか?ぜひ教えてほしい。仕事用の端末ではなく、非業務用のデバイスから Signal で joseph.404 までメッセージを送るか、joseph@404media.co 宛てにメールをいただければ幸いだ。
EasyOptOuts の共同創業者であるタイラー・マーフィー氏は、Hide My Email ユーザーの実際のメールアドレスを特定できることを発見しました。当時、マーフィー氏は「問題の全容は不明だが、ボランティアを使った限定的なテストでは、Hide My Email アドレスの 100% が悪用可能だった」と述べています。その中には私自身も含まれており、実際に検証を行いました。
マーフィー氏がこの問題を Apple に報告したのは 2025 年 6 月でした。その後数ヶ月にわたり、Apple は調査中と回答し、修正済みだと発表しました。しかしマーフィー氏は依然として悪用可能であることを確認し、再度調査を求めました。Apple が根本的な解決に至らない可能性があると判断したマーフィー氏は、Apple が脆弱性を把握してから約 1 年後の現在、404 Media に連絡を取りました。
数週間前に 404 Media がこの問題を初めて報じた際、悪用方法を詳細に記述しませんでした。それは Apple がまだ修正を行っていなかったためです。もし具体的な手法を公開すれば、第三者がその仕組みを解明して悪用し、人々の実際のメールアドレスを暴露する恐れがあったからです。
Apple は今回の脆弱性が修正されたと発表しています。簡単に言えば、対象となる「Hide My Email」ユーザーにスパムとして拒否されたメッセージを送信する必要がありました。
「隠されたメールアドレスがメールログに漏洩した頻度は不明です。多くの主要なメールホストでは、正当なメールであっても自動的にスパムとして拒否されるだけで漏洩が発生しました。こうしたメールは受信トレイには届かないため、スパムフォルダを確認して自分が影響を受けたかどうかを調べることはできません」と、Murphy 氏と EasyOptOut の共同創設者である Ben Weiner 氏は新しい声明で述べています。
「Apple の Hide My Email で隠されたメールアドレスが送信者に漏洩する原因となったバグは修正されました。しかし、Hide My Email ユーザーに対するリスクが完全に消えたとは考えていません。悪意のないメールでもバウンス(返送)して隠されたアドレスが露呈する可能性がある上、メール転送ログは長期間保持されることが多いため、2026 年 7 月 7 日以前に作成された Hide My Email アドレスに関連付けられたすべての隠されたメールアドレスが既に漏洩し、第三者のログに残っている可能性が高いと推測しています」と続けています。
PCMag の報道によると、Apple に対する集団訴訟では、この機能のために顧客が支払った購読料金の全額返還を求めるとともに、Apple の「欺瞞的な行為」に対して差し止め命令を出すことを求めています。
原文を表示
imageApple says it has fixed a vulnerability in its Hide My Email feature which let essentially anyone figure out a user’s real email address which was supposed to be protected by the feature. Apple only fixed the vulnerability after 404 Media wrote about it at the start of July, despite Apple knowing about the issue for more than a year.
The news also follows the filing of a class action lawsuit against Apple over the vulnerability.
On Wednesday Apple told 404 Media it deployed a patch for the issue on July 3, which the company says has fully resolved the issue.
Hide My Email is part of Apple’s paid iCloud+ product. It lets customers quickly create a new, anonymous email address they can then use to sign up to websites, services, or email people with. The generated email addresses typically contain two random words followed by a number and the @icloud.com domain. I use it heavily so hackers may have a harder time cross-referencing my activity and accounts across data breaches, for example.
Do you know about any other privacy issues like this? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.
Tyler Murphy, co-founder of EasyOptOuts, discovered he was able to find the real email address of Hide My Email users. At the time, Murphy said, “We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.” That included mine, which we tested.
Murphy first reported the issue to Apple in June 2025. Over the subsequent months, Apple said it was looking into the issue and said it had fixed it; Murphy found it was still exploitable; and Apple again said it was looking into it. Murphy, thinking Apple may not fix the issue at all, then contacted 404 Media, around a year after Apple learned of the vulnerability.
When 404 Media first covered the issue several weeks ago, we did not include any details on how it worked because Apple had not fixed it. Meaning, if we published more specifics, third parties might figure out how to exploit it and reveal peoples’ real email addresses.
Now Apple says it has been fixed, we can add that, in simple terms, it required sending a target Hide My Email user a message that got rejected as spam. “We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected,” Murphy and EasyOptOut co-founder Ben Weiner said in a new statement.
“The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. However, we don't think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs,” they added.
The class action lawsuit against Apple seeks full recovery of the subscription costs customers paid for the feature and an injunction against Apple for its “deceptive conduct,” PCMag reported.
関連記事
今日のまとめ
AI日報で今日の重要ニュースをまとめ読み