Apple’s premium privacy feature, built directly into iOS and Safari, can silently leak a user’s real IP address, according to researchers who discovered a series of flaws in the system. This isn't a catastrophic hack, but it exposes a predictable reliability gap in a service millions pay for and base their privacy on. The core promise of iCloud Private Relay | to stop websites from seeing your IP address | can be circumvented by a malicious website or even happen incidentally during normal browsing according to TechCrunch. This directly erodes trust in Apple’s premium privacy marketing.

Your Sneaky iPhone Flaw Exposes Your Real Location
XOOMAR Intelligence
Analyst Take
Researchers Talal Haj Bakry and Tommy Mysk found the problem lies in WebKit, Apple's web browser engine that underpins Safari and all other browsers on iOS. Notably, this also impacts third-party browsers like OnionBrowser, an app for accessing the Tor anonymity network. For users, the failure can be silent. You see a working website, but behind the scenes, your device’s true IP address is being exposed. The researchers have even set up a website where anyone can check if the flaw affects them, and in tests, it successfully returned real IP addresses.
How the Privacy Shield Was Supposed to Work
Private Relay isn't a classic VPN. A standard VPN creates an encrypted tunnel for all your device's traffic at the operating system level. iCloud Private Relay, by contrast, only works within Safari and focuses on obfuscating your DNS queries and IP address specifically from websites.
Think of it as a sophisticated two-stage mail forwarding service for your web requests.
- Your device sends a browsing request. Your real IP address is visible to your internet provider and to the first relay, operated by Apple. However, the website address you're trying to visit is encrypted.
- The request passes to a second relay, operated by a third-party partner like Cloudflare or Akamai. This relay decrypts the website’s address and connects to it, using a temporary, anonymous IP address generated solely for your browsing session.
The elegant design split is clear: Apple knows who you are but not where you're going; the third-party relay knows where you're going but not who you are. In theory, no single entity sees both, which is a strong privacy model. This premium service is only available to iCloud+ subscribers, making the subsequent bug sting more.
The Exact Technical Leak That Breaks the Chain
The flaw isn't in Apple's relay servers being hacked. It's in how WebKit, the browser engine, interfaces with other system services. The most direct leak involves passkeys, the secure WebAuthn-based authentication method Apple champions.
Here’s the breakdown: When a website using passkeys prompts for authentication, the request is handled not by Safari but by the operating system’s credential service. This system-level request operates outside the browser’s proxy path.
“Because the fetch is issued by the operating system’s credential service rather than by Safari, it never enters Private Relay’s proxied path. The destination server sees the device’s real IP address either way,” the researchers wrote.
In plain terms, any website that uses (or even pretends to use) passkeys can capture your real IP address, even with Private Relay active. You’d have no visual cue that this silent leak is happening; the login process appears normal. This isn't just a theoretical lab finding. The researchers' test site proves it works in the wild.
Furthermore, because all iOS browsers are required to use Apple's WebKit engine, the vulnerability isn't confined to Safari. The creators of OnionBrowser confirmed that at least two of the identified leaks directly affect their app, calling the core issues "dire" and entirely in Apple's hands to fix. This means even users seeking stronger anonymity via Tor on iOS could have their IP exposed.
Why a Single Bug Undermines the Entire Promise
This glitch is bigger than one software patch. It strikes at the core expectation users have for a premium, integrated privacy tool: that it works reliably. When a feature is marketed as "always on" protection, a silent failure is worse than no feature at all.
Users in sensitive situations | journalists, activists, or anyone avoiding location tracking | might rely on Private Relay as their primary shield. They assume the "on" switch means "protected." This bug reveals the dangerous gap between that perception and the nuanced reality of complex, cloud-dependent privacy tech.
This incident follows a pattern in Apple's privacy features. Just last month, as we reported, Apple Accuses 11 Ex-Employees of Taking Secrets to OpenAI and a bug was disclosed in Apple’s Hide My Email feature that revealed real email addresses. According to 404 Media, Apple knew about that bug for over a year before fixing it. These repeated issues with Apple's paid-for privacy products start to paint a picture of an ambitious privacy suite where robustness may be trailing behind the marketing.
What Users Can Do Right Now
Until Apple releases a fix, users should understand that Private Relay cannot be considered a bulletproof solution for high-stakes privacy needs. Here’s a practical action plan:
For General Browsing: Keep Private Relay on. For everyday use, it still provides a significant privacy boost against common trackers and your internet provider. Just be aware of its limitations.
For Truly Sensitive Sessions: For tasks where exposing your real IP address carries serious risk, the safest course is to temporarily disable Private Relay for that specific network or session and use a reputable, dedicated VPN service. A true VPN operates at the system level and provides a more consistent, audited layer of protection.
Verify Your Current Status: You can visit the researchers' verification website to see if your real IP is leaking right now. This is the most direct way to check your current exposure.
The researchers behind this discovery, who also develop a private browser called Psylo, stated they didn't report the bug to Apple due to past experiences of "months of delays, inconsistent communication, and in some cases, denying the issue’s impact entirely." Apple told 404 Media it is investigating the report.
What Apple's Fix Must Build Beyond the Code
Patching the specific WebKit flaw is the bare minimum. To rebuild trust, Apple needs to address the opaque nature of Private Relay's operation. The lack of user-facing status indicators is a critical flaw in a privacy product.
First, Apple should add a persistent, clear visual indicator in Safari's UI when Private Relay is actively proxying traffic, akin to the VPN icon on other platforms. This lets users see the protection is live.
Second, the system needs alerts for failure. If the connection to the relay servers drops or a request is forced to bypass the proxy (as with the passkey flaw), users should be notified. An audible alert or a persistent on-screen warning would prevent silent failures.
Third, Apple must foster a more transparent relationship with external security researchers. The researchers' cited reluctance to report is a red flag for a company that positions itself as a privacy leader. Fixing bugs promptly and credibly is part of the security lifecycle.
Ultimately, for privacy technology, transparency about failures is as vital as the encryption itself. Users need to know not just that a tool exists, but when it’s working and, critically, when it isn’t. As Apple navigates increased regulatory scrutiny over its ecosystem, like the EU's Digital Markets Act that is forcing interoperability changes as seen in Apple Must Let iPhones Paste to Windows PCs in EU, the robustness and transparency of its core services will be under an equally intense microscope.
Why This Changes Everything
- This flaw fundamentally undermines the core privacy promise of a premium, paid service millions of users rely on.
- It raises concerns about the security of Apple's ecosystem, as the weakness is in WebKit, the engine powering all iOS browsers.
- Users may believe they are anonymous while their real IP address is silently leaked, putting their location and identity at risk.
Comparing Private Relay to a Standard VPN
| Feature | iCloud Private Relay | Standard VPN |
|---|---|---|
| Scope of Protection | Only within Safari, focusing on DNS and IP address from websites | Creates an encrypted tunnel for all device traffic at the OS level |
| Encryption Scope | Encrypts the website you're trying to visit (DNS/URL) | Encrypts all traffic and connection metadata |
| Relay Architecture | Two-stage relay: 1st by Apple, 2nd by third-party partner | Single encrypted tunnel to the VPN provider's server |
Sources
Written by
XOOMAR Insights Team
Research and Editorial Desk
The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.
Explore More Topics
Related Articles
TechnologyApple Must Let iPhones Paste to Windows PCs in EU
Europe's regulators are forcing Apple to break a key ecosystem lock, requiring it to let iPhone users copy text and paste it directly onto Windows PCs by 2027.
TechnologyiPhone Runners Snag Spotify Running Mode as Android Waits
Spotify Running Mode turns Premium iPhone playlists into guided runs, with 25 presets and a launch that leaves many users waiting.
TechnologyDon't Trash Your Intel Mac Yet: 6 Fresh Lives After Support Dies
Apple is ending macOS support for Intel Macs, but you can still get years of use by repurposing it as a dedicated media server, a home file vault, or a secure b
TechnologyFitbit Apple Health Sync Finally Ends iPhone Workarounds
Google Health 5.05 finally lets Fitbit data flow straight into Apple Health, closing a long-running iPhone workaround.
TechnologySmartphone Subscriptions Turn iPhone Upgrades Into Habit
Apple Upgrade makes the phone a monthly habit, using leases and resale value to pull users into the next device.
TechnologyLucid Delays Its Affordable EV to Avert 'Existential' Crisis
Lucid Motors delayed its vital $50k Cosmos EV by over a year, pivoting from mass-market dreams to survival mode with deep cuts and a risky bet on robotaxis.
TechnologyReddit Abandons Its Karma System for AI Mod Bots
Reddit is replacing community karma rules with AI moderation, aiming to remove barriers for new users and boost daily engagement at the cost of its original cul
Global TrendsNew Mexico Sues DOJ for Sabotaging Epstein Investigation
New Mexico has filed a federal lawsuit against the Justice Department, accusing it of obstructing the state's investigation into crimes at Jeffery Epstein's Zor
SaaS & ToolsShopify Triples Traffic, Sales as AI Defies Google's Drop
Shopify is reporting a sharp uptick in AI-driven traffic and sales, showing the tool can fuel commerce even while it saps media publishers.
TechnologyReddit Gives AI Ultimate Power to Ban Users
Reddit is gambling its entire community governance by replacing its old AutoModerator system with an AI that interprets rule “intent,” fundamentally shifting po
Don't miss the signal
Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.
Free forever. No spam. Unsubscribe anytime.