메뉴
BL
404 Media 7일 전

애플, '내 이메일 가리기' 실제 주소 노출 취약점 finally 조치

IMP
7/10
핵심 요약

애플의 유료 서비스인 '내 이메일 가리기(Hide My Email)'에서 실제 이메일 주소가 노출되는 심각한 취약점이 1년 넘게 방치된 끝에 패치되었습니다. 스팸으로 반송되는 이메일의 로그를 통해 익명 주소가 추적되는 방식이었으며, 이 문제는 언론 보도 직후에야 수정되었습니다. 현재 애플을 상대로 소비자 피해 보상을 요구하는 집단 소송이 진행 중입니다.

번역된 본문

애플이 '내 이메일 가리기(Hide My Email)' 기능의 취약점을 수정했다고 밝혔습니다. 이 취약점은 사실상 누구나 기능에 의해 보호되어야 할 사용자의 실제 이메일 주소를 알아낼 수 있게 만들었습니다. 애플은 이 문제를 인지한 지 1년이 넘었음에도 불구하고, 404 Media가 7월 초 이를 보도한 이후에야 취약점을 조치했습니다. 이 소식은 해당 취약점과 관련하여 애플을 상대로 집단 소송이 제기된 직후에 전해진 것입니다. 수요일, 애플은 404 Media에 이 문제에 대한 패치를 7월 3일에 배포했으며 문제가 완전히 해결되었다고 밝혔습니다.

'내 이메일 가리기'는 애플의 유료 서비스인 iCloud+의 일부 기능입니다. 사용자는 웹사이트나 서비스에 가입하거나 이메일을 보낼 때 사용할 수 있는 새롭고 익명화된 이메일 주소를 빠르게 생성할 수 있습니다. 생성된 이메일 주소는 일반적으로 두 개의 무작위 단어와 숫자, 그리고 @icloud.com 도메인으로 구성됩니다. 필자의 경우, 데이터 유출 사고에서 해커가 나의 계정과 활동을 교차 추적하기 어렵게 만들기 위해 이 기능을 적극적으로 사용합니다.

💡 이와 유사한 다른 개인정보 보호 문제를 알고 계신가요? 여러분의 제보를 기다립니다. 업무용 기기가 아닌 개인 기기를 이용해 Signal(joseph.404)로 안전하게 메시지를 보내거나 joseph@404media.co로 이메일을 보내주시면 됩니다.

EasyOptOuts의 공동 창립자인 타일러 머피(Tyler Murphy)는 '내 이메일 가리기' 사용자의 실제 이메일 주소를 찾아낼 수 있다는 사실을 발견했습니다. 당시 머피는 "이 문제의 전체 범위는 알 수 없지만, 자원봉사자들을 대상으로 진행한 제한된 테스트 결과 100%의 '내 이메일 가리기' 주소가 취약점 악용의 표적이 될 수 있었습니다"라고 말했습니다. 이에는 우리가 직접 테스트한 필자의 주소도 포함되었습니다.

머피는 2025년 6월에 처음으로 이 문제를 애플에 보고했습니다. 이후 몇 달에 걸쳐 애플은 문제를 조사 중이며 수정했다고 밝혔고, 머피가 여전히 악용 가능하다는 사실을 발견하면 애플은 다시 조사 중이라고 답변하는 일이 반복되었습니다. 애플이 취약점을 인지한 지 약 1년이 지난 후, 머피는 애플이 이 문제를 아예 수정하지 않을 수도 있다고 생각하여 404 Media에 연락했습니다.

404 Media가 몇 주 전 이 문제를 처음 보도했을 때, 애플이 아직 해결하지 않았기 때문에 작동 방식에 대한 구체적인 세부 내용은 포함하지 않았습니다. 구체적인 내용을 공개하면 제3자가 이를 악용하여 사람들의 실제 이메일 주소를 알아내는 방법을 파악할 수 있기 때문입니다. 이제 애플이 해결을 완료했다고 밝혔으므로 구체적인 내용을 덧붙이자면, 간단히 말해 대상 사용자의 '내 이메일 가리기' 주소로 스팸으로 간주되어 거부되는 메시지를 발송하는 방식이었습니다.

머피와 EasyOptOut 공동 창립자인 벤 와이너(Ben Weiner)는 새로운 성명에서 "숨겨진 이메일 주소가 이메일 로그에서 얼마나 자주 유출되었는지는 알 수 없습니다. 많은 주요 이메일 제공업체에서, 정상적인 메시지라 하더라도 자동으로 스팸으로 거부되는 것만으로도 유출이 발생했습니다. 이러한 이메일은 받은편지함에 도달하지 않았을 가능성이 높으므로, 스팸함을 확인하여 자신이 영향을 받았는지 알아낼 수 없습니다"라고 말했습니다.

그들은 "애플의 '내 이메일 가리기'가 발신자에게 숨겨진 이메일 주소를 유출하게 만든 버그는 수정되었습니다. 그러나 사용자에 대한 위험이 완전히 제거되었다고는 생각하지 않습니다. 악의가 없는 일반 이메일도 반송되면서 숨겨진 이메일 주소가 노출될 수 있고, 메일 전송 로그는 종종 장기간 보존되기 때문에, 2026년 7월 7일 이전에 생성된 '내 이메일 가리기' 주소와 연결된 모든 실제 이메일은 노출되었거나 여전히 제3자 로그에 남아 있을 수 있다고 가정해야 합니다"라고 덧붙였습니다.

PCMag에 따르면, 애플을 상대로 제기된 집단 소송은 소비자들이 해당 기능을 위해 지불한 구독 비용의 전액 환불과 애플의 '기만적인 행위'에 대한 금지 명령을 요구하고 있습니다.

저자 소개: 조셉(Joseph)은 사회적 파급력을 창출하는 데 중점을 두는 수상 경력이 있는 탐사 보도 기자입니다. 그의 보도는 수억 달러 규모의 벌금을 부과하게 만들고, 기술 기업을 폐업하게 만드는 등 큰 변화를 이끌어냈습니다. 조셉의 더 많은 기사 보기

원문 보기
원문 보기 (영어)
Apple says it has fixed a vulnerability in its Hide My Email feature which let essentially anyone figure out a user’s real email address which was supposed to be protected by the feature. Apple only fixed the vulnerability after 404 Media wrote about it at the start of July, despite Apple knowing about the issue for more than a year. The news also follows the filing of a class action lawsuit against Apple over the vulnerability. On Wednesday Apple told 404 Media it deployed a patch for the issue on July 3, which the company says has fully resolved the issue. Hide My Email is part of Apple’s paid iCloud+ product. It lets customers quickly create a new, anonymous email address they can then use to sign up to websites, services, or email people with. The generated email addresses typically contain two random words followed by a number and the @ icloud.com domain. I use it heavily so hackers may have a harder time cross-referencing my activity and accounts across data breaches, for example. 💡 Do you know about any other privacy issues like this? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co. Tyler Murphy, co-founder of EasyOptOuts , discovered he was able to find the real email address of Hide My Email users. At the time, Murphy said, “We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.” That included mine, which we tested. Murphy first reported the issue to Apple in June 2025. Over the subsequent months, Apple said it was looking into the issue and said it had fixed it; Murphy found it was still exploitable; and Apple again said it was looking into it. Murphy, thinking Apple may not fix the issue at all, then contacted 404 Media, around a year after Apple learned of the vulnerability. When 404 Media first covered the issue several weeks ago, we did not include any details on how it worked because Apple had not fixed it. Meaning, if we published more specifics, third parties might figure out how to exploit it and reveal peoples’ real email addresses. Now Apple says it has been fixed, we can add that, in simple terms, it required sending a target Hide My Email user a message that got rejected as spam. “We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected,” Murphy and EasyOptOut co-founder Ben Weiner said in a new statement. “The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. However, we don't think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs,” they added. The class action lawsuit against Apple seeks full recovery of the subscription costs customers paid for the feature and an injunction against Apple for its “deceptive conduct,” PCMag reported . About the author Joseph is an award-winning investigative journalist focused on generating impact. His work has triggered hundreds of millions of dollars worth of fines, shut down tech companies, and much more. More from Joseph Cox