Apple’s Private Relay leaks your IP address, and it could be a long wait for a fix

Apple sells iCloud+ subscribers on the promise that Private Relay keeps your IP address hidden from websites, advertisers, and even Apple itself. That promise has a hole in it. According to Engadget, security researchers Talal Haj Bakry and Tommy Mysk have found that a flaw in WebKit, Apple’s browser engine, can expose your real IP address in ways that Private Relay simply doesn’t catch.

The specific trigger is passkeys. Passkeys are the increasingly popular password-free login method that major platforms have been pushing hard over the past two years. When you use one to log in through Safari, your device makes an authentication request outside the browser itself. That’s the problem. Private Relay is an iCloud+ feature tied to Safari’s browsing activity. It’s not a system-wide VPN. Anything happening outside the browser’s own traffic flow doesn’t get masked, and that authentication request is enough to hand your real IP to whatever site or service you’re logging into.

But the exposure doesn’t stop at Safari. Because the flaw is in WebKit, which Apple requires all iOS browsers to use, the same leak can happen in privacy-focused browsers like OnionBrowser and the researchers’ own Psylo browser. That’s a significant problem. People who go out of their way to use Tor-based browsers on iPhone do so specifically because they want strong anonymity. Finding out that the underlying engine undermines that effort will sting.

The researchers have already reached out to OnionBrowser and the Tor Project to share both their findings and potential fixes. Apple told 404Media it’s investigating the report. So it knows. The uncomfortable question is how long users will be exposed before anything changes.

History here is not encouraging. The researchers pointed to a separate issue involving iCloud’s Hide My Email feature, where a different team found it was leaking real email addresses behind aliases in mid-2025. Apple didn’t ship a fix until a full year later. A year is a long time to be quietly leaking identifying information you believed was protected.

This matters beyond the technical details. Privacy tools only work if they do what they say. When a feature marketed as a privacy shield has a known flaw, and the vendor’s response timeline can stretch to twelve months, users are left making decisions based on false assumptions. Private Relay isn’t worthless, but right now, anyone using passkeys on iOS should understand it’s not covering all the bases. And that’s worth knowing before you assume you’re protected.