Skip to main content

Apple's iCloud Private Relay Can Actually Expose Your Real IP Address

Flaws in Apple's web browser engine and passkey handling can compromise the IP-masking service and reveal real user data.

AI-written
Inewgen
06 Aug 2026Source: Lifehacker3 min read (0 views)
Share
Apple's iCloud Private Relay Can Actually Expose Your Real IP Address

Stock photo for illustration only, not from the actual event

Font size
  • 404 Media reports that flaws in Apple's browser engine allow IP addresses to be exposed.
  • Web requests made outside the browser bypass the protections of Private Relay entirely.
  • Websites supporting passkeys can view users' actual IP addresses directly.
  • Using a dedicated VPN remains a safer bet for full-device encryption and privacy.

If you rely on iCloud Private Relay, Apple's paid IP address masking service, your internet browsing activity might not be as private as you think. According to a report by 404 Media, vulnerabilities in Apple's web browser engine can expose user IP addresses either maliciously or incidentally, even when those addresses are supposed to remain hidden from prying eyes.

iCloud Private Relay, bundled with an iCloud+ subscription, is designed to conceal both your identity and the websites you visit while using Safari. Without it, network providers and visited websites can view your IP address and DNS records, which facilitate long-term tracking of your location and browsing habits. The system aims to encrypt DNS records and generate a temporary IP address, preventing any single entity, including Apple, from obtaining both pieces of information.

This vulnerability highlights the inherent limitations of platform-integrated privacy features, especially as new authentication standards like passkeys introduce complex web request behaviors. When underlying protocols operate outside standard browser sandboxes, built-in masking tools can fail, demonstrating why auxiliary security layers often require external, dedicated alternatives.

smartphone privacy settings interface

Stock photo for illustration only, not from the actual event

The issue was uncovered by security researchers Talal Haj Bakry and Tommy Mysk and relates directly to how passkeys function. Web requests are executed outside the browser environment and outside the protections of Private Relay, meaning any website supporting passkeys can see the user's real IP address. While this naturally impacts Safari traffic, the researchers also detected the exact same flaw in Onion Browser, an iOS app that routes and encrypts traffic through the Tor network. Both 404 Media and TechCrunch verified this vulnerability through independent testing.

Never miss the latest news?

Subscribe to get news summaries by email - not often enough to be annoying.

โฆษณา

The researchers noted that they informed Apple about the flaw but have not received a timeline for when a patch will be deployed. Although Apple typically maintains a solid reputation regarding privacy, this is not the first notable lapse in recent months. Back in July, the company's "Hide My Email" masking service was found to contain a vulnerability that exposed real email addresses, an issue Apple reportedly knew about for over a year despite claiming to have patched it.

While Private Relay can serve as a useful privacy utility when functioning as intended, it is not a true Virtual Private Network (VPN) because protection is strictly limited to Safari browsing. For users wanting to keep their IP addresses hidden and data encrypted across every app and browser on their device, utilizing a separate VPN service is strongly recommended.

Source: Lifehacker

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article