Urgent.News

What's breaking now, across thousands of outlets.

Tech

Apple’s Private Relay Isn’t So Private After All, Can Leak Your IP Address

Surprisingly, one culprit behind the leak is passkey technology, which is supposed to be a more secure way to authenticate data such as site logins.

Apple’s Private Relay Isn’t So Private After All, Can Leak Your IP Address

Apple's iCloud Private Relay, a feature meant to safeguard users' web traffic, has been found to potentially expose users' IP addresses, according to recent revelations by security researchers. This feature, available to paid iCloud Plus subscribers, routes web traffic through proxy servers to conceal the user's IP address and the websites they visit.

However, researchers Talal Haj Bakry and Tommy Mysk uncovered that despite Private Relay being active, the IP address of the device or home network can still be transmitted, potentially revealing a user's identity or location.

The researchers set up a test website to demonstrate this vulnerability. When tested on an iPhone 17 Pro and a MacBook Pro with Private Relay enabled, the test site successfully identified the user's home internet router's IP address. In response to the findings, the researchers chose to disclose the issue publicly rather than wait for Apple's potentially lengthy response. They cited Apple's history of delayed communication and denial of issues in the past.

The vulnerability is attributed to three main factors. Firstly, passkeys, a more secure user authentication method, bypass the Private Relay proxy and send user information directly from the device, exposing the real IP address. Secondly, DNS prefetching, a technique websites use to speed up connections, can also bypass the Private Relay mechanism and reveal the user's IP address, provided the site includes specific HTML code.

Lastly, WebTransport, a low-latency method, allows WebKit to open a direct connection to the website, bypassing Private Relay and exposing the user's IP address.

Apple has not yet responded to a request for comment on the matter. The researchers emphasized that they felt compelled to go public with their findings due to past experiences with Apple's slow and inconsistent response to reported issues. They argue that these bugs undermine the core privacy guarantees that Private Relay and other Mysk browsers, such as Psylo and iOS Tor, are designed to provide.

Written by urgent.news from CNET's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at cnet.com →

More in Tech

[$] LWN.net Weekly Edition for August 6, 2026

Inside this week's LWN.net Weekly Edition: Front : Process-builder API; Fedora COI; FUSE io_uring buffer sizes; BPF network namespaces; FUSE plans; BPF libraries; directory creation system call.

How does auth work?

Folks, I just published two videos that go together: how authentication works, and how authorization works. They both get lumped together a lot when someone says "Auth", but understanding the…

More from Thursday 6 August →