A significant security vulnerability has come to light affecting Apple's Private Relay, the premium privacy service bundled with iCloud+ subscriptions. Research published in early August reveals that the feature, which Apple markets as a shield against tracking and IP address exposure, contains fundamental flaws that can inadvertently reveal users' actual Internet protocol addresses to websites and online services. The discovery raises fresh questions about the effectiveness of Apple's privacy protections at a time when the technology giant has positioned itself as a defender of user privacy in an increasingly surveillance-conscious digital landscape.
The vulnerability originates from three separate flaws embedded within WebKit, the browser engine that Apple mandates all iOS browsers must use. Since Apple's App Store policies require this single engine across Safari and all third-party iOS browsers, the exposure affects a far broader user base than Private Relay subscribers alone. Independent cybersecurity researchers Talal Haj Bakry and Tommy Mysk uncovered the issue after investigating a DNS leak reported by a user of Psylo, a privacy-focused browser the duo developed. Their findings, detailed in a cybersecurity blog post on August 4, documented how users' real IP addresses become visible to websites, completely negating Private Relay's intended protection mechanism.
The irony of this situation is particularly striking given how the flaw emerges from Apple's own security infrastructure. Private Relay, initially launched in 2021, operates through a two-relay system designed to ensure that no single entity—not even Apple itself—can simultaneously observe a user's identity and their browsing behaviour. The system functions by routing traffic through multiple servers that separate user identity from browsing activity. However, the researchers identified that when users employ passkeys, a security mechanism Apple has been actively promoting as a superior alternative to traditional passwords, the protection crumbles. Passkeys require a user's device to make authentication requests that circumvent the normal browser pathway, thereby bypassing Private Relay entirely and exposing the user's genuine IP address to the authenticating service.
This technical shortcoming illustrates a common challenge in cybersecurity: the friction between layered security measures. Passkeys represent a genuine advancement in authentication security, eliminating the vulnerabilities associated with password-based systems. Yet by operating outside the browser framework, they create an unexpected backdoor that undermines the privacy protections users believed they had activated. For Malaysian users who subscribe to iCloud+ specifically for Private Relay's privacy guarantees, this represents a meaningful betrayal of that trust. The vulnerability is particularly consequential given that IP addresses reveal not merely a user's approximate location down to postal code precision, but also enable Internet service providers, website operators, and potentially malicious actors to construct comprehensive records of browsing patterns.
The scope of this security flaw extends beyond Private Relay users to encompass the entire iOS browser ecosystem. Since all iOS browsers must implement WebKit, every privacy-conscious user attempting to protect their identity through third-party privacy browsers such as Tor browsers and Onion Browser faces the same vulnerability. This mandatory standardization, while ostensibly designed to ensure consistency and security across the platform, has instead created a single point of failure that affects hundreds of millions of iOS users globally. The implications are particularly troubling for users in jurisdictions where Internet privacy is increasingly under pressure or where tracking poses genuine risks to personal safety or freedom of expression.
Apple's privacy positioning has been central to its brand identity and marketing strategy for years. The company launched an advertising campaign in June emphasizing Safari's purported privacy superiority compared to Chrome and other competitors, a message designed to differentiate Apple products in an increasingly privacy-conscious market. This vulnerability discovery undermines those claims precisely when Apple has been promoting privacy as a core differentiator. The company's Intelligent Tracking Prevention feature, introduced in 2017, was designed to hide users' IP addresses from trackers. Private Relay represented an evolution of this commitment, promising even more robust protection. For consumers making purchasing decisions based on Apple's privacy assurances, particularly in Southeast Asia where many users are newer to premium services like iCloud+, this flaw represents a material misrepresentation of product capabilities.
It is worth distinguishing between Private Relay and Safari's separate Private Browsing feature, a confusion that has muddied public understanding of Apple's privacy offerings. Private Browsing prevents Safari from retaining browsing history within individual tabs, providing limited session-based privacy. Private Relay, by contrast, functions at the network level, theoretically protecting user identity from external observers regardless of browsing application. The two serve different purposes, though both have been presented as components of Apple's privacy architecture. However, the WebKit vulnerabilities affect all iOS browsers attempting to provide privacy protections, collapsing these distinctions in practice.
The researchers have taken proactive measures to address the vulnerability's impact. Both Talal Haj Bakry and Tommy Mysk have updated their Psylo browser to defend against the identified flaws and have notified the Tor Project and Onion Browser developers, enabling those projects to implement protective measures. This responsible disclosure approach demonstrates appropriate cybersecurity practice, giving affected parties time to address vulnerabilities before widespread public awareness. Nevertheless, the fundamental architectural problem remains unresolved at Apple's level, requiring changes to WebKit itself or substantial modifications to how passkey authentication is handled within the privacy framework.
For Malaysian users and broader Southeast Asian consumers who have adopted Apple's privacy-focused messaging, this revelation warrants immediate practical consideration. Users currently relying on Private Relay for confidential browsing activities should understand that the protection may not function as advertised, particularly when authenticating through passkeys. Those handling sensitive communications or wishing to avoid surveillance should evaluate whether alternative privacy solutions offer more robust protection. The incident also highlights the risks inherent in entrusting privacy entirely to a single vendor's proprietary systems, however well-intentioned those systems might be in conception.
Apple has not publicly responded to requests for comment regarding the WebKit vulnerabilities or their implications for Private Relay users. The company's silence on this matter stands in contrast to the aggressive marketing of its privacy features to consumers. Until Apple addresses these fundamental flaws either through WebKit modifications or architectural changes to how passkeys interact with Private Relay, the privacy guarantees associated with the iCloud+ service remain substantially compromised. For a company that has built significant competitive advantage on privacy positioning, this vulnerability represents both a technical failure and a credibility challenge that extends beyond the technical community to mainstream users worldwide.
