Apple users who rely on iCloud Private Relay should know about a newly disclosed privacy weakness that may allow a website to discover a visitor’s real network details. Security researchers Talal Haj Bakry and Tommy Mysk report that three WebKit behaviours can bypass the proxy route used by Private Relay. The iCloud Private Relay IP leak does not mean every website automatically sees your address, but a specially prepared site may be able to trigger it.
The research is especially relevant to iPhone, iPad and Mac users with iCloud+. Here is what has been reported, how Private Relay normally works, and the practical steps users can take while waiting for platform-level fixes.
What is the reported iCloud Private Relay IP leak?
The researchers identified three WebKit features that they say can send requests outside a browser’s configured proxy path:
- DNS prefetching: a webpage can ask the browser to resolve a domain before it is needed. The researchers found that this lookup may use the device’s normal DNS route instead of the protected route.
- WebAuthn related-origin requests: the system credential service can fetch a validation file when a site uses, or appears to use, passkeys. Because the operating system makes that request rather than the normal webpage loader, the destination may receive the device’s real IP address.
- WebTransport: this web technology can establish a direct HTTP/3 connection that the researchers say may bypass an application-level proxy.
The original Mysk research report includes technical explanations and a proof-of-concept test. TechCrunch also reported that its test exposed the publication’s real IP address while Private Relay was in use.
How iCloud Private Relay normally protects Safari browsing
Apple explains that Private Relay sends Safari requests through two separate secure relays. The first relay can see the user’s IP address but not the requested website. The second relay connects to the destination using a temporary IP address. The design is intended to prevent any single party—including Apple—from connecting a person’s identity with their complete browsing activity.
Private Relay is included with iCloud+ and primarily protects Safari web browsing and DNS requests. It is important to understand that it is not a full-device VPN. A VPN can route a much broader range of device traffic through a system-level tunnel, while Private Relay has a narrower purpose.
Why the WebKit privacy issue matters
An IP address can reveal an approximate location, internet provider and network. It can also help websites connect visits or strengthen a device fingerprint. The reported flaws matter because users may reasonably expect Safari requests covered by Private Relay to avoid revealing their normal public IP address.
The weakness is not described as an account takeover, malware infection or loss of iCloud data. A site would need to invoke one of the affected behaviours and operate infrastructure capable of observing the resulting request. Even so, people with heightened privacy needs should treat the disclosure seriously.
iPhone browsers may share some exposure
On iPhone and iPad, browsers generally use Apple’s WebKit engine, although alternative browser-engine rules can differ in some regions. The researchers say WebKit-based proxy browsers can therefore encounter related bypasses. Their report also notes that system-level VPN connections are not affected by these specific application-proxy issues.
Which devices and software may be affected?
The report concerns WebKit on iOS, iPadOS and macOS, including Safari with iCloud Private Relay enabled. The researchers associate DNS prefetching with iOS 26.0 and later, WebAuthn related-origin requests with iOS 18.0 and later, and WebTransport with iOS 26.4 and later. Exact exposure can depend on the browser, feature and operating-system version.
Apple had not published a dedicated support advisory for these specific findings when this article was prepared. That distinction matters: the technical findings are publicly documented by the researchers and covered by multiple technology publications, but users should watch Apple’s official release notes for confirmed fixes.
What should Apple users do now?
- Keep Private Relay enabled for ordinary use. It can still provide meaningful protection for normal Safari traffic. Turning it off would remove that protection rather than solve the underlying WebKit behaviour.
- Install Apple updates promptly. Check Settings > General > Software Update on iPhone or iPad, or System Settings > General > Software Update on Mac. Back up important data before a major update.
- Use a reputable full-device VPN when stronger IP protection is essential. This is most relevant for journalists, researchers, activists and people handling sensitive work. Review the provider’s privacy policy because the VPN operator becomes a trusted intermediary.
- Avoid random “leak test” links. A test page is designed to collect network information. Use only a source you understand, and do not treat an unfamiliar test site as harmless.
- Follow Apple’s security information. Check the official Apple security releases page for future WebKit and operating-system fixes.
For more Apple privacy context, see our guide to the recent Hide My Email privacy fix.
Final thoughts
The iCloud Private Relay IP leak research highlights a gap between browser-level proxy protection and network activity initiated elsewhere in the operating system. Most users do not need to panic or disable Private Relay, but they should understand its limits, keep their devices current and consider a trustworthy VPN when hiding a real IP address is critical.
Frequently asked questions
Does iCloud Private Relay leak every user’s IP address?
No. The research describes specific WebKit behaviours that a website may trigger. It does not show that every page or normal Safari request automatically reveals the real IP address.
Is iCloud Private Relay the same as a VPN?
No. Private Relay mainly protects Safari browsing and related DNS activity. A full-device VPN generally routes a wider range of network traffic through its tunnel.
Should I turn off Private Relay?
For most people, no. Disabling it removes the privacy protection it still provides for ordinary Safari browsing. Keep it enabled, update your software and use additional protection if your threat level requires it.
Are passkeys insecure because of this report?
The disclosure concerns how a related-origin validation request is routed, not the cryptographic security of passkeys themselves. Passkeys remain a strong defence against password theft and phishing.
How will I know when Apple fixes the issue?
Review Apple’s software update notes and security release page. A confirmed fix may appear in WebKit, Safari, iOS, iPadOS or macOS release documentation.

Leave a Reply