A vulnerability in Apple's iCloud Private Relay service allows websites to bypass privacy protections and expose users' real IP addresses [1].
This flaw undermines a core security promise for millions of Apple users who rely on the service to mask their digital identity and location while browsing the web.
Security researchers reported the issue earlier this month [3]. The vulnerability stems from three specific WebKit features [1] that operate outside the protection of the Private Relay system. When these features are triggered, they create a bypass that reveals the user's actual IP address to the website being visited [1], [6].
One of the primary triggers for this leak occurs during passkey requests [5]. Passkeys are designed to replace traditional passwords with more secure cryptographic keys, but the process of requesting one can inadvertently leak the user's identity via their IP address [5].
This exposure occurs when users browse with Safari or other browsers based on the WebKit engine [4]. Because the leak happens at the browser engine level, the privacy shield provided by iCloud Private Relay is effectively neutralized during these specific interactions [6].
Apple has acknowledged the flaw and provided a timeline for the resolution. The company said the issue will be fixed in fall 2026 [5]. Until that update is released, users may remain vulnerable to IP tracking when utilizing the affected WebKit features [4].
“A vulnerability in Apple's iCloud Private Relay service allows websites to bypass privacy protections.”
The discovery highlights a persistent challenge in privacy engineering: the 'leakage' that occurs when a secure tunnel must interact with legacy or specialized web protocols. By exposing the IP address during passkey requests, the flaw creates a paradox where a security-enhancing feature (passkeys) simultaneously weakens a privacy-enhancing feature (Private Relay).


