Security researchers have found that iCloud Private Relay, Apple’s paid privacy feature included with iCloud+ subscriptions, is exposing users’ real IP addresses to websites under certain conditions. Apple told 404 Media it is investigating the issue.
The flaw was documented by researchers Tommy Mysk and Talal Haj Bakry, who found that certain passkey authentication requests bypass Safari entirely.
Because Private Relay only protects Safari traffic, those requests can reveal a user’s real IP address to the destination server.
The Leak Happens Before You Know It
The exposure doesn’t require users to click anything. A website using WebAuthn’s “conditional” mediation setting can trigger the request silently in the background without displaying a visible passkey prompt. Users receive no warning.
Apple says Private Relay prevents websites from seeing a user’s IP address and location while browsing in Safari. The researchers found that protection doesn’t apply in every case.
The researchers uncovered two additional WebKit behaviors with similar privacy implications.
DNS prefetching, introduced in iOS 26, can reveal a user’s real DNS servers, while WebTransport, added in iOS 26.4, can expose an IP address under certain conditions.
Because both originate in WebKit, the issue also affects third-party browsers built on Apple’s browser engine.
Also: Apple is taking one of the iPhone’s smartest features somewhere most people never expected it to go
Why This Matters to Every iCloud+ Subscriber
Private Relay is one of the headline privacy features included with every iCloud+ subscription.
The researchers’ findings don’t mean the feature is broken, but they do show there are situations where websites can still obtain a user’s real IP address.
Mysk and Haj Bakry also published a public testing tool that lets users check whether their setup is leaking their IP address.
Apple has not released a fix. Until then, users who rely on IP masking should treat Private Relay as partial protection rather than complete anonymity.
A full VPN remains the more comprehensive option because it routes all device traffic through an encrypted tunnel instead of protecting only browser traffic.