Apple’s Private Relay is supposed to hide your IP address. Researchers have found three ways it does not.
The paid feature, part of an iCloud+ subscription, masks your real IP address while you browse in Safari. But three flaws in WebKit, Apple’s browser engine, quietly route some traffic around it. Security researchers Talal Haj Bakry and Tommy Mysk laid out the leaks this week. 404 Media, which broke the story, verified that a test site could read a protected user’s real IP.
The most alarming of the three involves passkeys. “Any website that supports, or pretends to support, passkeys can see the user’s real IP address despite having iCloud Private Relay on,” Mysk said. Opening the site is enough. A log-in never has to happen.
Three ways out of the tunnel
Private Relay routes Safari’s traffic through two relays, so no single party sees both who you are and where you go. The catch is that not all of a page’s traffic takes that path.
The passkey leak is the sharpest. When a page asks for a passkey tied to another domain, the operating system’s credential service fetches a small validation file itself, straight from the device. It never passes through Private Relay, and the destination server sees the real IP. No prompt appears, and the user never has to touch a passkey.
The other two are quieter. DNS prefetching, a speed trick, resolves a site’s addresses through the device’s normal path and leaks the real DNS servers. WebTransport, a newer connection type, opens a direct link that skips the proxy and exposes the IP. All three live in WebKit and defeat any browser that leans on its proxy settings.
It breaks iOS Tor too
That last point matters more than it sounds. Apple requires every browser on the iPhone to use WebKit. So the flaws are not Apple’s alone to suffer. They also hit iOS browsers built for anonymity, including OnionBrowser, which routes traffic over the Tor network.
The official Tor Browser, on desktop, is unaffected. So are VPNs, which tunnel a whole device’s traffic at the system level rather than one app’s. Private Relay was never a full VPN, and Apple says as much. That gap is exactly what the flaws exploit.
One limit is worth stating. The leak exposes an IP address and some DNS data, and nothing more, Mysk said. And to tie a leaked IP to a specific browsing session, a site has to be built to exploit the bug on purpose. Any passkey site can see the address. Weaponising it takes intent.
Apple’s privacy problem
The timing is bad for a company that sells privacy as a feature. Barely a month ago, 404 Media found Apple’s Hide My Email tool was exposing real email addresses, an issue Apple reportedly knew about for over a year before fixing. “July: Apple’s Hide My Email leaks real emails. August: Apple’s Private Relay leaks real user IPs,” ProtonVPN wrote.
The researchers did not use Apple’s usual channel at first, citing a history of slow responses and disputed impact. They published, then sent Apple the link anyway. Within a day, the status on their report flipped to “we’re planning to address the issue you reported,” with a fix slated for autumn 2026. In public, Apple would only say it is investigating.
There is a caveat on the messengers. Bakry and Mysk build a rival iOS browser, Psylo, and shipped a version this week that closes all three leaks by default. That gives them a stake in the story, though the bugs are real and reproducible. Mostly it is a reminder that Apple’s security response tends to move fastest under a spotlight, and that a privacy feature can fail in ways a user never sees.
Get the TNW newsletter
Get the most important tech news in your inbox each week.