A significant privacy vulnerability has emerged in Apple's Private Relay service, one of the company's flagship privacy-focused offerings, according to findings from cybersecurity researchers. The flaw allows user IP addresses to leak onto the internet even when subscribers believe they are protected by the premium iCloud+ privacy feature, raising fresh questions about the effectiveness of Apple's privacy protections just as the technology giant continues marketing its devices as privacy-centric alternatives to competitors.
The vulnerability was identified by cybersecurity researchers Talal Haj Bakry and Tommy Mysk, who initially discovered the issue while investigating reports from users of Psylo, a private browsing application they developed. After receiving complaints about DNS leaks on certain websites, the duo conducted a deeper investigation and uncovered not just one but three separate flaws within WebKit, Apple's proprietary browser engine. These flaws have the capacity to expose a device's actual IP address, undermining the entire purpose of Private Relay.
The technical roots of the problem trace back to Apple's strict control over iOS browser architecture. Under the App Store's policies, every iOS browser—including Safari, third-party privacy browsers, and Tor-based applications—must utilise WebKit as their underlying engine. This means that when these browsers attempt to route traffic through Private Relay's proxy system, they are simultaneously vulnerable to the same WebKit-based leaks. The implications extend far beyond Safari users; every privacy-focused application on the iOS platform that depends on WebKit's proxying capabilities is potentially affected, including all Tor browsers available on iOS and privacy-focused alternatives like Psylo.
Private Relay, which Apple introduced in 2021 as part of its iCloud+ subscription service, operates through a two-relay architecture designed to ensure that neither Apple nor any other entity can simultaneously observe both a user's identity and their browsing activity. The service was positioned as a comprehensive solution to prevent IP address exposure and reduce tracking vulnerabilities. However, the researchers identified a peculiar irony in how one of Apple's additional security features—passkeys, which represent a more secure authentication method than traditional passwords—actually circumvents Private Relay's protections entirely.
When users authenticate using passkeys, their devices must make authentication requests that bypass the browser environment and, by extension, bypass Private Relay's protective relay system. This occurs because passkeys require direct device-to-server communication outside the normal browsing pathway. The consequence is that a user's real IP address becomes visible to websites and potentially to broader internet infrastructure monitoring, completely defeating the purpose of having subscribed to Private Relay in the first place. This creates a situation where Apple's own security innovations inadvertently create privacy vulnerabilities.
Understanding why IP address exposure matters is crucial for Malaysian users and others across Southeast Asia who increasingly value their digital privacy. An IP address functions as a unique identifier that reveals not only a user's approximate geographical location—often down to the postal code level—but also enables internet service providers, website operators, and other entities to establish detailed browsing patterns and track online activity. This capability extends beyond mere surveillance; malicious actors regularly exploit exposed IP addresses to launch specific categories of cyberattacks, including DDoS attacks that can overwhelm a target's internet connection and other forms of network-based exploitation.
The discovery comes at a particularly awkward moment for Apple's privacy narrative. In June, the company launched a major advertising campaign specifically highlighting Safari's privacy advantages over competitors like Google Chrome, emphasising the superiority of its privacy protections. Apple's privacy positioning has been central to its brand strategy for years, dating back to its introduction of Intelligent Tracking Prevention in 2017, a feature designed to shield users from tracker-based IP address collection. Private Relay represented an evolution of this privacy philosophy, offering an additional layer of encryption and anonymity for premium subscribers willing to pay extra for enhanced protection.
The distinction between Private Relay and Safari's separate Private Browsing mode is important to clarify, particularly for users who may assume these features provide equivalent protection. Safari's Private Browsing mode focuses on preventing local storage of browsing history and cookies within the browser itself, providing limited protection against external tracking. Private Relay, by contrast, was intended to provide end-to-end protection against all forms of IP-based tracking and location inference. The vulnerability therefore represents a more serious breach of what users were promised they would receive by activating Private Relay.
The researchers have already taken steps to mitigate the immediate impact. They updated their Psylo browser to include protections against these specific WebKit flaws and notified the Tor Project and Onion Browser developers so they could implement similar safeguards in their own applications. However, the broader vulnerability remains embedded in Apple's WebKit, meaning that any iOS browser relying on Apple's proxying application programming interface remains exposed unless Apple directly addresses the underlying architectural issues. The vulnerability highlights a tension between Apple's tight control over the iOS ecosystem and the ability to deliver truly comprehensive privacy protections.
Apple has not publicly responded to inquiries regarding this vulnerability or its plans to address the underlying WebKit issues. The silence raises questions about the timeline for fixes and whether Apple intends to modify its App Store policies to allow alternative browser engines that might not share these particular vulnerabilities. For Malaysian and Southeast Asian users who have invested in iCloud+ subscriptions specifically for Private Relay's promised protections, the discovery underscores the importance of relying on multiple layers of privacy protection rather than trusting any single feature or service to provide complete anonymity and security.
