{
  "id": 3325857,
  "title": "Apple Quietly Fixes iCloud Private Relay Vulnerability in iOS 26.6.1",
  "url": "https://urgent.news/2026/08/25/apple-quietly-fixes-icloud-private-relay-vulnerability-in-ios-26-6-1",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-25T18:24:05.000Z",
  "source": {
    "name": "CNET",
    "slug": "cnet",
    "url": "https://www.cnet.com/tech/services-and-software/apple-quietly-fixes-icloud-private-relay-vulnerability-in-ios-26-6-1/"
  },
  "original_language": "en",
  "account": "Apple's iCloud Private Relay feature has been restored to its private status following a fix in iOS 26.6.1 that resolved a vulnerability. This paid feature, exclusive to iCloud Plus subscribers, routes web traffic through proxy servers to conceal a user's IP address and location. However, a vulnerability was discovered which could still expose the IP address under certain conditions. Researchers Talal Haj Bakry and Tommy Mysk identified the issue, creating a webpage to test if devices were vulnerable. The vulnerability was patched in iOS 26.6.1, as evidenced by the leaks.psyop.app webpage reporting masked IP addresses instead of actual ones when iCloud Private Relay was enabled. Apple's swift response to the vulnerability, which Mysk noted as unlikely given Apple's typical response time, led to a lawsuit from Clarkson Law Firm, the firm behind a $250 million settlement with Apple over Apple Intelligence advertising.",
  "summary": "The problem could leak your device’s IP address, even when the paid iCloud Plus feature was enabled.",
  "key_points": [
    "Apple restored iCloud Private Relay in iOS 26.6.1",
    "Vulnerability exposed IP addresses under certain conditions",
    "Researchers identified issue, Apple patched it swiftly"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}