Summary created by Smart Answers AI
In summary:
- Macworld reports that security researchers discovered a critical flaw allowing websites to bypass iCloud Private Relay and obtain users’ real IP addresses, even when using Safari.
- The vulnerability stems from Passkey requests operating outside Safari’s Private Relay protection, affecting WebKit-based browsers and compromising user privacy.
- Apple has acknowledged this dire issue but hasn’t provided a fix timeline, prompting recommendations for traditional VPN services for comprehensive device protection.
A pair of security researchers found a critical problem with Apple’s iCloud Private Relay feature. Even when using Safari, a website can fairly easily get your real IP address.
Researchers Talal Haj Bakry and Tommy Mysk just disclosed the issue. Apple is aware of it; according to a report form 404 Media, Mysk said, “We have already informed them. They said the issue was ‘dire,’ but they let us disclose the issue. They didn’t provide any time when they will address this.”
Here’s how it works, in basic terms: iCloud Private Relay is a nice security feature but it is not a VPN. It only works when you use Safari. Passkeys—the helpful biometric alternative to remembering different passwords for every site—operate outside the browser, using the WebAuthn framework on Apple devices. So if you set up a website to make a request for a Passkey credential origin, it’s not protected by iCloud Private Relay because the Passkey request is technically happening outside the browser.
Of course, if you’re an everyday user, you don’t have any reason to know or suspect this. You’re using Safari, you have the paid iCloud+ Private Relay service turned on, you should be hidden, right?
The issue also affects browsers that use WebKit’s proxy relay, including some Tor browsers. The researchers built a proof-of-concept site you can use to check if you’re affected.
We don’t know when Apple is going to address the issue, but a vulnerability in Hide My Email that exposed real email addresses was fixed very quickly by Apple after the issue became public. That only required a back-end server fix, while this iCloud Private Relay issue might require a software update on devices. The fact that Apple let the researchers disclose the issue before the fix means Apple wants users to know about the problem and suggests it could take some time to fix.
iCloud Private Relay is not a VPN
This is a good time to remind everyone that iCloud Private Relay is not a VPN. A traditional VPN routes all the internet traffic for your entire device through other servers, sometimes providing other features as well at the core network level. iCloud Private Relay operates only in the Safari browser. It’s a nice perk of iCloud+, but not a full VPN substitute.
That difference is the root cause of this new issue. You can be browsing with Safari and a website can make a special kind of request that happens outside the usual browser stack—by design—and thus is not affected by iCloud Private Relay. Apple will obviously need to address this quickly.
If you’re interested in a real VPN, check out our list of the best VPNs.



