Looks like that was the original article, which didn't have much details about how the exploit worked.
> 404 Media is not revealing the exact details of the vulnerability because it can still be exploited as of Monday, when 404 Media verified the issue with one of our own hidden email addresses.
However, based on the current article:
> Now Apple says it has been fixed, we can add that, in simple terms, it required sending a target Hide My Email user a message that got rejected as spam. “We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected,” Murphy and EasyOptOut co-founder Ben Weiner said in a new statement.
My guess is that if an e-mail was rejected as Spam, the response had the actual e-mail included. However, based on the next paragraph:
> “The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. However, we don't think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs,” they added.
It seems even bounced e-mails could leak your actual e-mail.
Same. Although with the curse of hindsight, I painfully recall choosing to run SETI@home instead of "mining" some weird digital currency called Bitcoin back in 2010. So, painful.
Exactly the same here. Ran SETI@home on all my machines back in the day. I remember running this weird bitcoin ‘thing’ for an entire week on my main machine which generated around 1.4 btc. Then I DELETED it.
Nobody with a sub-4% is VOLUNTARILY going to sell. Home prices have slowly dropped to adjust for interest rate increases. However, a "price reset" will probably occur in areas where folks need to sell due to financial hardship.
Credit Card usage has already seen an increase, savings contributions have dropped, and car loans payments have seen more defaults. Unfortunately, folks are struggling these days.
A sudden "panic sell" of just a few homes could cause overall homes values in a neighborhood to drop, thus "correcting" or "resetting" over-inflated prices. Unfortunately, this would be a doomsday-scenario for many folks who bought recently in the 6-7% with inflated prices. Until interest rates dropped, they're stuck with a terrible payment while being severely underwater for their homes.
Can you imagine if THEY need to sell? Suddenly the value of their home doesn't even cover their mortgage. Now you're talking bankruptcy for many folks...
> Neutral stance: We're not convinced that the complexity this feature introduces upon the HTML parser carries its weight in terms of usefulness for web developers. There's also a risk that the processing model is not compatible with a future declarative custom elements feature as it was developed in isolation. Having said that, the proposal is a reasonable approach for this functionality that takes into account the various constraints and security considerations that come with changing the HTML parser.
> Positive Stance: This is a reasonable proposal which takes into account the various constraints and security considerations that come with changing the HTML parser.
Hopefully that's a sign of things to come! (Fingers crossed)
It's interesting. My right wing family also now loves him, but they just love Elon. They would never consider a Tesla because it's what the "left" drive in California, neither of which they want to be associated with.
Yep. I once tried to create a cartoon dinosaur with hair in the “style” of an ex President (yellow and combed forward), and was warned with a potential ban.
> 404 Media is not revealing the exact details of the vulnerability because it can still be exploited as of Monday, when 404 Media verified the issue with one of our own hidden email addresses.
However, based on the current article:
> Now Apple says it has been fixed, we can add that, in simple terms, it required sending a target Hide My Email user a message that got rejected as spam. “We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected,” Murphy and EasyOptOut co-founder Ben Weiner said in a new statement.
My guess is that if an e-mail was rejected as Spam, the response had the actual e-mail included. However, based on the next paragraph:
> “The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. However, we don't think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs,” they added.
It seems even bounced e-mails could leak your actual e-mail.