Logo
TechDefused
Aug 6, 2026 12:29 PM

Researchers found flaws in a cloud-relay feature that can reveal a user’s real IP address during web-authentication flows. The findings indicate certain OS-level requests can bypass the service’s proxy path.

Apple’s iCloud Private Relay can expose users’ real IP addresses, security researchers reported after building tests that returned unmasked IPs to destination sites.

The leaks are caused by three WebKit flaws that allow certain operating-system-level requests to bypass Private Relay’s proxy path, including requests triggered by passkeys via WebAuthn.

“In short: any website that supports, or pretends to support, passkeys can see the user’s real IP address despite having iCloud Private Relay on,” Tommy Mysk, one of the researchers, told 404 Media.

Because all iOS browsers must use Apple’s WebKit engine, the researchers found the issues affect at least one Tor client on iOS, with OnionBrowser showing exposure while the official Tor Browser is not impacted, the report says.

The researchers developed a site to demonstrate the problem and said it returned real IP addresses in 404 Media’s tests.

Private Relay is offered as part of iCloud+ and is not a true virtual private network, routing only Safari traffic rather than all device network activity.

Apple told 404 Media it is investigating the report, and the researchers disclosed the WebKit flaws on August 4.

Comments
anonymous profile image
Powered by RoundtableBuilt on infrastructure designed for real-time media. Learn more at RTB.io.© Roundtable 2026. By using this site you agree to the Terms of Use and Privacy Policy