Apple’s iCloud Private Relay Flaw Exposes Real IP Addresses Despite Privacy Protections
A newly disclosed vulnerability in WebKit the browser engine powering iOS and Safari undermines the privacy protections of Apple’s iCloud Private Relay, potentially exposing users’ real IP addresses. Researchers Tommy Mysk and Talal Haj Bakry identified the issue, which was later verified by 404media, demonstrating that a malicious website could bypass Private Relay’s safeguards by exploiting passkey authentication requests.
The flaw occurs when a site supports or falsely claims to support passkeys, triggering a separate network request outside Safari’s protected relay route. Since this request bypasses Private Relay’s proxy, the user’s actual IP address is revealed to the destination server. The attack requires no user interaction beyond visiting a compromised site and engaging with a passkey prompt, making it a low-effort method for tracking or profiling visitors.
Apple has acknowledged the report and is investigating, though no fix has been released. The exposure is particularly concerning because IP addresses can reveal a user’s approximate location, internet provider, and other identifying details, which could aid stalkers, advertisers, or targeted attackers in deanonymizing browsing sessions.
The issue also affects OnionBrowser, an iOS app that routes traffic through the Tor network. Due to Apple’s requirement that all iOS browsers use WebKit, the app inherits the same vulnerability under certain configurations. However, the official Tor Browser remains unaffected, reinforcing its position as the more reliable option for strong anonymity.
Unlike full-device VPNs, iCloud Private Relay only protects Safari traffic, leaving other system-level requests such as those from passkey authentication exposed. This limitation highlights the need for users and organizations to recognize the tool’s boundaries rather than treating it as a comprehensive privacy solution.
While the flaw does not involve malware or account takeovers, it represents a significant privacy risk, particularly for users relying on Private Relay to obscure their online activity. Until Apple issues a patch, security teams are advised to review passkey implementation flows, and site owners should avoid treating detected IP addresses as definitive identity signals.
Source: https://cybersecuritynews.com/apple-icloud-private-relay/
Apple TPRM report: https://www.rankiteo.com/company/apple
"id": "app1785997496",
"linkid": "apple",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'iCloud Private Relay users, '
'OnionBrowser users',
'industry': 'Consumer Electronics, Software, Services',
'location': 'Global (primarily Cupertino, California, '
'USA)',
'name': 'Apple',
'size': 'Large (Fortune 500)',
'type': 'Technology Company'}],
'attack_vector': 'Passkey authentication requests',
'customer_advisories': 'Users relying on iCloud Private Relay for privacy '
'should be aware of its limitations and consider '
'alternative solutions like Tor Browser for stronger '
'anonymity.',
'data_breach': {'personally_identifiable_information': 'IP addresses '
'(indirectly)',
'sensitivity_of_data': 'High (can reveal location, ISP, and '
'other identifying details)',
'type_of_data_compromised': 'Real IP addresses'},
'description': 'A newly disclosed vulnerability in WebKit, the browser engine '
'powering iOS and Safari, undermines the privacy protections '
'of Apple’s iCloud Private Relay, potentially exposing users’ '
'real IP addresses. The flaw occurs when a site supports or '
'falsely claims to support passkeys, triggering a separate '
'network request outside Safari’s protected relay route, '
'revealing the user’s actual IP address to the destination '
'server.',
'impact': {'brand_reputation_impact': 'Significant privacy risk for users '
'relying on Private Relay',
'data_compromised': 'Real IP addresses (approximate location, '
'internet provider, identifying details)',
'systems_affected': 'iOS and Safari (via WebKit), iCloud Private '
'Relay, OnionBrowser (Tor-based iOS app)'},
'investigation_status': 'Under investigation by Apple',
'lessons_learned': 'iCloud Private Relay has limitations and does not provide '
'comprehensive privacy protection like full-device VPNs or '
'Tor Browser. Users and organizations should recognize its '
'boundaries.',
'motivation': 'Tracking, profiling, or deanonymizing users',
'post_incident_analysis': {'corrective_actions': 'Apple is investigating; no '
'specific corrective actions '
'disclosed yet',
'root_causes': 'WebKit vulnerability allowing '
'passkey authentication requests to '
'bypass iCloud Private Relay’s '
'proxy'},
'recommendations': 'Review passkey implementation flows, avoid treating '
'detected IP addresses as definitive identity signals, and '
'consider using Tor Browser for stronger anonymity until a '
'patch is released.',
'references': [{'source': 'Tommy Mysk and Talal Haj Bakry (Researchers)'},
{'source': '404media'}],
'response': {'remediation_measures': 'Apple is investigating; no patch '
'released yet'},
'stakeholder_advisories': 'Security teams should review passkey '
'implementation flows and recognize the limitations '
'of iCloud Private Relay.',
'title': 'Apple’s iCloud Private Relay Flaw Exposes Real IP Addresses Despite '
'Privacy Protections',
'type': 'Privacy Vulnerability',
'vulnerability_exploited': 'WebKit vulnerability in iCloud Private Relay'}