A significant privacy vulnerability has emerged in Apple's flagship privacy protection service, raising concerns for millions of users who pay for enhanced data protection. Security researchers have discovered that Apple's iCloud+ Private Relay—a premium feature marketed as a safeguard against online tracking and location exposure—inadvertently reveals user IP addresses in certain circumstances, undermining the very protection it promises to deliver.
The problem originates from flaws embedded in WebKit, the browser engine that Apple mandates all iOS applications use. Since every browser on iPhone and iPad must leverage WebKit's core technology, the vulnerability affects the entire ecosystem of privacy-focused applications on the platform. This includes not only Apple's own Safari browser but also third-party applications like Tor Browser and Psylo, a privacy-focused browser developed by security researchers Talal Haj Bakry and Tommy Mysk. The researchers identified three distinct flaws within WebKit that cause Domain Name System leaks—failures in the encryption and tunneling system that expose a device's actual IP address to external parties.
The vulnerability was publicly disclosed on August 5 through a cybersecurity research blog, following initial investigation prompted by a Psylo user who reported suspicious DNS leaks while browsing certain websites. Bakry and Mysk, who work both as cybersecurity specialists and application developers, subsequently traced the issue to its source and identified two additional exposure vectors. Their findings revealed that Private Relay subscribers remained vulnerable despite paying for protection, as the feature's architecture contained fundamental design flaws that could be exploited under specific conditions.
The irony underlying this vulnerability lies in how it exploits one of Apple's own security innovations. Private Relay, introduced in 2021 as part of iCloud+ subscriptions, employs a dual-relay architecture designed to ensure that no entity—not even Apple itself—can simultaneously access a user's identity and browsing habits. The system functions by routing traffic through two separate relay points, fragmenting user data across multiple systems. However, the vulnerability emerges when users employ passkeys, Apple's recommended replacement for traditional passwords. Passkeys represent a significant security advancement in authentication, generating and validating cryptographic credentials without transmitting passwords across networks. Yet because passkeys require authentication requests to occur outside the normal browser environment, these requests circumvent Private Relay's protective tunnels entirely, directly exposing the device's IP address to verification servers.
IP addresses function as digital identifiers for internet-connected devices, serving as essential infrastructure for online communication and data routing. However, they present significant privacy concerns for users. An IP address reveals approximate geographic location down to postal code level, enabling internet service providers, website administrators, and analytics companies to establish detailed movement and browsing patterns. Beyond surveillance implications, malicious actors weaponise IP addresses to orchestrate distributed attacks, launch targeted intrusions, and conduct reconnaissance on specific targets. The combination of location disclosure and attack surface expansion explains why privacy advocates emphasise IP address concealment as fundamental to digital security.
Apple has positioned itself as a privacy-first technology company, distinguishing its products through ostensibly superior privacy controls compared to competitors. The company launched a substantial advertising campaign in June highlighting Safari's purported privacy advantages over Google Chrome, emphasizing user data protection as a core differentiator. This privacy-focused branding extends back to 2017, when Apple introduced Intelligent Tracking Prevention—a Safari feature restricting trackers' ability to access user IP addresses and browsing history. Private Relay represented the logical evolution of this philosophy, offering paying subscribers enterprise-grade privacy infrastructure.
The distinction between Private Relay and Safari's Private Browsing feature reveals Apple's multi-layered approach to privacy, though it also suggests potential confusion among users. Private Browsing mode prevents Safari from storing browsing history, cookies, and search records within that specific session, though it does not hide the user's IP address or prevent tracking by websites and internet service providers. Private Relay, conversely, operates at the network level, concealing IP addresses and encrypting traffic patterns regardless of which applications or websites users access. The separation reflects different threat models: Private Browsing protects against local device access, while Private Relay protects against network-level observation.
The researchers have already implemented protective measures within their Psylo browser and notified relevant stakeholders including the Tor Project and Onion Browser developers. However, Safari users—the largest iOS browser population—remain reliant on Apple's remediation efforts. The vulnerability's scope across the entire iOS ecosystem underscores the risks inherent in Apple's mandatory WebKit requirement. By centralising browser engine control, Apple ensures consistency and enables privacy features but simultaneously creates a single point of failure affecting billions of devices.
Apple has not publicly responded to requests for comment regarding the vulnerability, nor has the company issued a timeline for fixes. The absence of acknowledgment or transparency contrasts sharply with the company's privacy marketing claims. Users who subscribed to iCloud+ specifically for Private Relay protection now face uncertainty about their actual security posture. For Malaysian users and the broader Southeast Asian market, where digital surveillance and data monetization present escalating privacy threats, the implications extend beyond individual security concerns to questions about whether premium privacy products deliver promised protections.
