iCloud Private Relay Exposes Real IP Addresses, Researchers Find
Security researchers have discovered a flaw in Apple's iCloud Private Relay feature, which can inadvertently expose users' real IP addresses to certain websites, particularly those utilizing passkeys.

Security researchers Tommy Mysk and Talal Haj Bakry have identified a significant vulnerability in Apple's iCloud Private Relay service, a feature designed to enhance user privacy by masking IP addresses. The flaw allows certain websites to access a user's genuine IP address, undermining the core protective function of the paid iCloud+ feature.
iCloud Private Relay is intended to obscure a user's IP and DNS information when browsing the web through Safari. However, it functions differently from a full VPN and does not shield all device traffic. The vulnerability specifically arises when websites employ passkeys, which leverage the WebAuthn standard. While passkeys store private keys on the user's device, the system's requests to websites are not inherently protected by Private Relay. This is because WebKit, Apple's browser engine, hands over WebAuthn ceremonies to the operating system's credential service. This service then issues the HTTPS request directly from the device, bypassing the Private Relay proxy and revealing the user's actual IP address to the destination server.
Researchers demonstrated that a malicious actor could set up a website incorporating WebAuthn to exploit this vulnerability. Crucially, these IP leaks can occur without any visible passkey prompt or user interaction, making detection difficult. This means users might be unaware their real IP address has been compromised in the background.
Additional WebKit Vulnerabilities Revealed
The investigation by Mysk and Haj Bakry extended beyond passkey-related leaks, uncovering two other features within WebKit that can expose sensitive user data. DNS prefetching, a feature introduced in iOS 26, has been found to reveal a user's real DNS servers. Furthermore, WebTransport, implemented in iOS 26.4, can also leak a user's IP address. These discoveries add to concerns about the privacy protections offered by Apple's ecosystem.
These vulnerabilities are not isolated to Safari. Because the issue is integrated into the core workings of WebKit, some third-party browsers that utilize the engine are also affected. This broad impact means that a wider range of users may be exposed to potential privacy breaches.
Apple has reportedly been notified of the findings and has stated that it is investigating the matter. In the interim, security experts suggest that users seeking more robust privacy protections may need to consider using a Virtual Private Network (VPN) as an alternative or supplement to iCloud Private Relay. A VPN encrypts all internet traffic from a device, offering a more comprehensive layer of anonymity than the current implementation of Private Relay allows in these specific scenarios.
The discovery highlights the ongoing challenges in maintaining robust online privacy, especially as new authentication methods like passkeys become more prevalent. While Apple has long been a proponent of user privacy, this incident underscores the need for continuous vigilance and security updates to protect against evolving threats.
