iCloud Private Relay Can Leak Your Real IP Address, Researchers Say

iCloud

Apple’s marquee privacy feature has a hole in it, and the researchers who found it have a track record worth taking seriously. Tommy Mysk and Talal Haj Bakry, the same pair who previously exposed a flaw in Hide My Email say iCloud Private Relay can leak a user’s real IP address to any website that supports, or simply pretends to support, passkeys, even with the feature fully enabled.

The mechanism comes down to how WebKit handles passkey validation. iCloud Private Relay only protects traffic that flows through Safari’s normal browsing path; it’s not a system-wide VPN. But WebAuthn requests, the standard behind passkeys, get handed off to iOS’s own credential service instead of staying inside Safari, and that service fires its request directly from the device rather than through Private Relay’s proxy. A site doesn’t even need to show a visible passkey prompt to trigger it; the leak happens silently in the background.

This isn’t a single bug, either. Mysk and Haj Bakry identified three separate leak paths in total: WebAuthn Related Origin Requests, which have existed since iOS 18; DNS prefetching, introduced in iOS 26.0; and WebTransport, which only shipped in iOS 26.4 this past March. All three bypass whatever proxy a browser has configured, meaning the problem extends beyond Safari to any iOS browser built on WebKit Apple requires every iOS browser to use it including at least one Tor-focused browser, OnionBrowser, though the standalone Tor Browser itself uses a different engine and isn’t affected.

Apple has acknowledged the report and is investigating, but per Mysk, the company only said the issue was “dire” without committing to a fixed timeline. In the meantime, the researchers built a test page at leaks.psylo.app where anyone can check whether their own IP is leaking, and released an update to their own Psylo browser that disables all three vulnerable features by default.

The practical takeaway is straightforward: if you’ve been paying for iCloud+ specifically to keep your browsing IP hidden from the sites you visit, that protection currently has real gaps a motivated site operator could exploit without your knowledge. A traditional system-level VPN isn’t affected by any of this, since it encrypts all device traffic rather than routing through Safari-specific relays worth considering as a stopgap until Apple actually patches WebKit.


Discover more from Phoonomo

Subscribe to get the latest posts sent to your email.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top

Discover more from Phoonomo

Subscribe now to keep reading and get access to the full archive.

Continue reading