Security researchers have discovered a problem with Apple’s iCloud Private Relay service. While the feature is meant to protect your real IP address, it might actually be leaking it to websites.

A new iCloud Private Relay problem

This iCloud Private Relay vulnerability was discovered by security researchers Tommy Mysk and Talal Haj Bakry, who detailed the problem in-depth on their website.

“In short: any website that supports, or pretends to support, passkeys can see the user’s real IP address despite having iCloud Private Relay on,” they say.

As a refresher, iCloud Private Relay is not a VPN. As we’ve explained before, it only protects your IP address in Safari, whereas VPNs protect all traffic from your device by running at the system level.

As 404 Media explains, the problem is due to a series of issues in Apple’s WebKit engine and how it handles passkeys.

In a quirk of how passkeys work — a broadly secure alternative to usernames and passwords which use the WebAuthn standard — a user’s device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user’s real IP address, even though to them it may look like they are simply interacting with a website as normal.

“Because the fetch is issued by the operating system’s credential service rather than by Safari, it never enters Private Relay’s proxied path. The destination server sees the device’s real IP address either way,” the researchers write in their research.

The impact of the problem is worsened on iOS, where all browsers are required to use Apple’s WebKit engine (in most countries):

Because all web browsers on iOS have to use Apple’s WebKit engine, the researchers also found the issues impact at least one Tor browser, called OnionBrowser. The Tor anonymity network routes users’ traffic through multiple nodes located all over the world. But some of the newly discovered issues can expose their IP address too.

Mysk says they reported the problem to the Tor Project, which said it was “dire.” Nonetheless, the company reportedly didn’t provide a timeline on when the problem will be fixed, but agreed to let Mysk disclose it anyway.

Mysk also filed a security report with Apple, the status of which currently says a fix is planned for Fall 2026: “We’re planning to address the issue you reported.”

You can check whether the problem impacts you via a website set up by the security researchers.

Today’s report follows a separate bug impacting Apple’s Hide My Email feature. This vulnerability, which allowed anyone to access a user’s real email address, was fixed by Apple last month.

Chance’s favorites

Follow ChanceThreadsBlueskyInstagram, and Mastodon.

FTC: We use income earning auto affiliate links. More.