Apple's Private Relay Can Leak Your Real IP Address
Researchers said three WebKit flaws let Safari users’ hidden IP addresses leak despite Apple’s Private Relay, which is limited to iCloud+ subscribers.
- Security researchers discovered a flaw in Apple's Private Relay that exposes real IP addresses when users interact with websites supporting credential authentication. TechCrunch verified the vulnerability on Tuesday.
- The vulnerability stems from how Apple's WebKit engine handles credential requests, which bypass the Private Relay path through the operating system. The destination server receives the device's actual IP address instead of a masked one.
- Researchers Tommy Mysk and Talal Haj Bakry established a website where users can verify if their device leaks a real IP address. The flaw also impacts the Tor-based OnionBrowser because all browsers must use WebKit.
- Researcher Tommy Mysk wrote that they chose not to report this issue to Apple because "reporting this issue would involve months of delays, inconsistent communication, and in some cases, denying the issue."
- Unlike a Virtual Private Network, which protects traffic system-wide, Private Relay functions only within Safari. Apple has not immediately responded to requests for comment about the vulnerability.
30 Articles
30 Articles
WebKit flaws expose real IP addresses across iOS, macOS browsers and iCloud Private Relay
Security researchers Talal Haj Bakry and Tommy Mysk, who build the Psylo privacy browser, disclosed three separate vulnerabilities in Apple's WebKit browser engine on Aug. 4, 2026. The flaws expose the real IP addresses and DNS requests of iOS and macOS users, cutting through protections built into proxy-based privacy browsers and Apple's own iCloud Private Relay. The discovery began with a complaint. A Psylo user flagged unusual DNS queries on …
In today's digital world, privacy is paramount. However, a new study has revealed a vulnerability in Apple's iCloud Private Relay tool that could compromise user privacy. Cybersecurity researchers have uncovered a security flaw in Apple's iCloud Private Relay tool, which could reveal a user's real IP address. How does iCloud Private Relay work? Introduced with iOS 15, iCloud Private Relay uses a two-channel architecture to ensure user privacy by…
Apple's Private Relay tool can leak users' IP addresses — with OnionBrowser also affected
Researchers Talal Haj Bakry and Tommy Mysk found three WebKit flaws leaking real IPs despite iCloud Private RelayDNS prefetching, WebAuthn origin requests, and WebTransport bypass proxy settings, exposing users across all Apple browsersTor and Psylo browsers issued fixes; Apple has not confirmed a patch but is reviewing the reportWebKit, Apple’s engine that powers all web browsers in its ecosystem, contained multiple flaws that helped leak the I…
Apple's iCloud Private Relay feature is leaking users' real IP addresses
The discovery comes from security researchers Talal Haj Bakry and Tommy Mysk, who found three WebKit features that bypass application-level proxy settings: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. WebKit underpins Safari and, in most countries, every other browser available on iOS.Read Entire Article
It turned out it was all about browsers. One of Apple's main privacy features was not as reliable as thought. Under certain conditions, iCloud Private Relay may disclose a user's network data. This is reported by RBC-Ukraine, referring to an analysis by cybersecurity researcher Mysk. The main problem is WebKit, which is the internal “engine” that runs Safari and all other iPhone browsers. According to Apple's rules, any browser in the App Store …
Coverage Details
Bias Distribution
- 79% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium















