Radio
Now Playing
Quickyla Radio — Click to play
Open →
3 min left
Back to News

Apple’s Private Relay isn’t always hiding your IP address, researchers say

Passkeys were supposed to fix our login headaches, but as we recently saw with Google Password Manager , transitioning to passwordless security can expose unexpected cracks in your privacy. Now, Appl…

Apple’s Private Relay isn’t always hiding your IP address, researchers say
Android Authority — 5 August 2026
Text:
30 0 0

Affiliate links on Android Authority may earn us a commission. Learn more.

Passkeys were supposed to fix our login headaches, but as we recently saw with Google Password Manager , transitioning to passwordless security can expose unexpected cracks in your privacy. Now, Apple is facing similar scrutiny after researchers uncovered a WebKit flaw that lets websites bypass iCloud Private Relay and expose users’ real IP addresses during passkey requests.

Discovered by security researchers Tommy Mysk and Talal Haj Bakry, the vulnerability centers on how WebAuthn requests interact with iOS (via 404 Media ). When a site prompts for a passkey or even pretends to support one, the network request isn’t processed inside Safari’s standard web browser stack. Instead, Apple’s system-level credential service steps in to handle the fetch directly.

That’s where the problem begins. iCloud Private Relay, which is part of Apple’s paid iCloud+ subscription, only protects traffic that passes through Safari, so these system-level requests bypass it entirely. As a result, a website can see your real IP address, even if you think it’s being hidden. According to the report, users wouldn’t notice anything unusual because the interaction appears to happen as part of a normal passkey flow.

The fallout isn’t limited to Safari. Because Apple requires every iOS browser to build on its WebKit engine, alternative browsers face the exact same exposure. The flaw even leaks real IP addresses on privacy-focused apps like OnionBrowser on the Tor network. Fortunately, traditional system-wide VPNs remain unaffected because they encrypt traffic at the OS level rather than relying on application proxies.

To help users verify the behavior, the researchers created a test website that checks whether a device’s real IP address is exposed. Tests reportedly confirm that it returns the actual IP address of a device that has iCloud Private Relay enabled.

If the findings hold up, they’d mark the second high-profile privacy issue involving an Apple subscription feature in recent weeks, following a flaw in Hide My Email that exposed users’ real email addresses before Apple eventually patched it. Unlike that issue, however, this latest report is still under investigation, so it’s unclear when — or how — Apple plans to address it.

Thank you for being part of our community. Read our Comment Policy before posting.

Read Full Story at Android Authority →
Advertisement
React:
Sponsored

More to Read

Hanwha Group and LG CNS tokenize trade receivables to enhan…
💻 Technology
Hanwha Group and LG CNS tokenize trade receivables to enhance supply chain finance
CoinDesk · 13 days ago
7 States’ Water Systems Hit by Cyberattacks Likely Tied to …
💻 Technology
7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
Wired · 7 days ago
Trump administration exempts SpaceX's Starlink from foreign…
💻 Technology
Trump administration exempts SpaceX's Starlink from foreign router ban
Ars Technica · 12 days ago
Here’s the biggest news you missed this weekend
🌍 World News
Here’s the biggest news you missed this weekend
NBC News · 13 days ago
The Vatican still hasn’t learned how to deal with abuse all…
🕌 Religion & Faith
The Vatican still hasn’t learned how to deal with abuse allegations
Crux Now · 13 days ago
Ghana's community service bill: A fix for the prison crisis?
🌍 World News
Ghana's community service bill: A fix for the prison crisis?
DW World · 12 days ago
Full view