Apple’s Private Relay Isn’t So Private After All, Can Leak Your IP Address
Apple's iCloud Private Relay feature is designed to obscure web traffic, but a new vulnerability means not all browsing is private. Security researchers discovered that even with iCloud Private Relay active, the IP address of a device or home network can be transmitted, w…
Intelligence analysis by Llama

A new vulnerability in Apple's iCloud Private Relay feature means that even with the feature enabled, the IP address of a device or home network can be transmitted, potentially revealing a person’s identity or location. This is a problem for users who rely on the feature for privacy.
Imagine you're sending a secret message to a friend, but someone can still see where you're sending it from. That's what's happening with Apple's iCloud Private Relay feature. Even with the feature enabled, the IP address of a device or home network can be transmitted, which could be used to reveal a person’s identity or location.
Analysis
A $60B Vote of Confidence in Apple's iCloud Private Relay Feature
Apple's iCloud Private Relay feature is designed to obscure web traffic, making it difficult for sites like advertisers, unscrupulous governments, or malicious attackers to trace that traffic back to the user. However, a new vulnerability has been discovered that means not all browsing is private, even with the feature enabled.
The researchers, Talal Hak Bakry and Tommy Mysk, set up a website that lets users check whether their connection is vulnerable. When tested using an iPhone 17 Pro and a MacBook Pro with iCloud Private Relay enabled, it correctly identified the IP address of the home internet router.
The researchers chose to make the vulnerability public rather than report it to Apple first. They noted that their past experience with Apple tells them that reporting the issue would involve months of delays, inconsistent communication, and in some cases, denying the issue’s impact entirely.
One problem is related to passkeys, the method of signing into sites that’s more secure and user-friendly than usernames and passwords. WebKit bypasses the Private Relay proxy and sends requested information directly from the device.
There are two other paths that can reveal the IP address even with iCloud Private Relay enabled. DNS prefetching is a way for websites to request data before it’s needed to speed up the connection. However, a site must include the code in its HTML to trigger it. The third vulnerability is with a low-latency method called WebTransport where WebKit opens a direct connection that bypasses the private relay and sends the user’s real IP address.
Apple’s security also took a hit recently when a bug in Apple’s iCloud Hide My Email feature seemed to expose people’s real email addresses. It, too, is a paid feature of iCloud Plus and is now the focus of a lawsuit accusing Apple of false advertising, fraud, and breach of contract.
Why This Matters
This story matters because it highlights a potential security risk for users who rely on Apple's iCloud Private Relay feature for privacy. The vulnerability could be used to reveal a person’s identity or location, which is a serious concern for anyone who values their online privacy.
The Road Ahead
Apple has not yet responded to a request for comment. However, the researchers have made the vulnerability public, and users can check whether their connection is vulnerable using the website set up by the researchers. It remains to be seen whether Apple will address the issue and provide a fix for the vulnerability.
Key points
- A new vulnerability in Apple's iCloud Private Relay feature means that even with the feature enabled, the IP address of a device or home network can be transmitted.
- The researchers, Talal Hak Bakry and Tommy Mysk, set up a website that lets users check whether their connection is vulnerable.
- The vulnerability is related to passkeys, DNS prefetching, and WebTransport, which can all reveal the IP address even with iCloud Private Relay enabled.
- Apple has not yet responded to a request for comment, and it remains to be seen whether the company will address the issue and provide a fix for the vulnerability.
Apple may address the issue and provide a fix for the vulnerability, which would improve the security of the iCloud Private Relay feature and provide users with a higher level of online privacy.
The vulnerability could be used to reveal a person’s identity or location, which is a serious concern for anyone who values their online privacy. If Apple does not address the issue, users may need to rely on other security measures to protect their online identity.

