
Recent reports reveal Apple’s iCloud Private Relay is leaking users’ real IP addresses
Researchers have discovered that Apple’s iCloud Private Relay, an iCloud+ feature designed to hide users’ IP addresses while browsing in Safari, can be bypassed through a Passkey WebAuthn request, potentially exposing the user’s real IP address.
The issue occurs because Passkey credential requests operate outside Safari’s standard browsing connection, so their network traffic is not routed through Private Relay. A website can initiate one of these requests and use the resulting connection to identify the visitor’s real IP address, despite the user browsing through Safari with the privacy feature enabled.
Researchers Talal Haj Bakry and Tommy Mysk traced the leak to three WebKit features, meaning some third party and Tor based browsers using WebKit’s proxy relay may also be affected. They did not privately report the issue to Apple, citing previous delays and disagreements over the impact of reported vulnerabilities, but published a proof of concept website that lets users check whether Private Relay is exposing their real IP address. Its also worth mentioning that Mysk and his colleagues also develop Psylo, a privacy focused browser that now includes mitigations against this type of leak.
Apple has not commented or provided a timeline for a fix, but this follows another iCloud related privacy flaw disclosed last month, when researchers found that the Hide My Email feature could actually expose users’ real email addresses.






Comments
Worth noting: the researchers who found this run a competing privacy browser that already mitigates it, and skipped private disclosure to Apple. Doesn't make the finding wrong, but it's relevant context. The root cause matters more than who found it, WebAuthn traffic bypassing Private Relay entirely is an architectural gap, not a config bug, which is why three WebKit features are implicated rather than one line of code. Second iCloud privacy miss in two months (after Hide My Email) is the real pattern worth watching, starts looking like a gap in how "privacy" features get validated, not just normal functionality.
"skipped private disclosure to Apple". Also worth noting they only started investigating after someone reported the issue to them and the researchers explain their actions (skipping private disclosure) being frustrated with Apple's string-pulling. So no, this isn't some spiteful company going after Apple.
I was expecting this, apple private relay seems more like a simple thing you can use to become a little more private (like cloudflare warp for example though that's better) and less of a thing you can use to do bad stuff and be untraceable
No single factor, most especially not a proprietary, closed-source one, can ever sufficiently make you "go private". This is the case for any VPN, including Mullvad and co., and, again, most definitely for Apple iCloud Private Relay. Anything claiming otherwise is false or misleading advertising.
Apples ecosystem is not a replacement for actually secure devices and practices
Standard iOS is more secure than standard Android. Standard macOS is more secure than Windows. I think you're talking about privacy here.
Sure but this is a comparison between the lesser of evils. Just because there are worse products, does not mean that apple is good or that it should be used by the masses
Wow what a shocker thankfully I used Mullvad VPN even since I started using it in 2022
Me too. I started with Mullvad VPN two years ago after my previous VPN (NordVPN) started leaking IPs. I thought this was because NordVPN is bloated beyond belief and some bloat components sent tracking info to the wrong places. Now I see that even dedicated services like Apple's one can do the same thing.