• 3 mins read
  • Published

Apple’s Private Relay Fails to Hide Real IP Addresses

Ken Doctor Media analyst FAYFO Media

by Ken Doctor

Apple’s Private Relay Fails to Hide Real IP Addresses FAYFO Media © fayfo.com
Apple’s Private Relay Fails to Hide Real IP Addresses © fayfo.com

Security researchers have uncovered flaws in Apple’s Private Relay, revealing that users’ real IP addresses can be exposed. The issue affects iOS browsers and even impacts some Tor-based apps.

Apple’s iCloud Private Relay for privacy may be at risk after researchers discovered that the tool can leak users’ real IP addresses. This vulnerability could have direct implications for audience data protection, source confidentiality, and the privacy of editorial workflows on iOS devices.

The flaws stem from Apple’s web browser engine, which underpins all browsers on iOS. According to security researchers Tommy Mysk and Talal Haj Bakry, these issues allow malicious websites to access the actual IP addresses of users who believe they are protected by Private Relay. The researchers also found that many websites may have already collected this information unintentionally. Notably, the leak affects not only Safari but also OnionBrowser, an iOS app designed to route traffic through the Tor anonymity network.

Private Relay, part of Apple’s paid iCloud+ subscription, is intended to mask users’ IP addresses while browsing in Safari. Apple’s documentation states that the feature prevents network providers and websites from seeing users’ IP addresses and DNS records, which could otherwise be used to identify individuals and track their browsing history. However, Private Relay is not a full VPN; it only covers Safari traffic, not system-wide network activity.

The core of the problem lies in how passkeys-an authentication method based on the WebAuthn standard-operate on iOS. When a user interacts with a website supporting passkeys, the device makes a web request outside the browser, bypassing Private Relay and exposing the real IP address. The researchers explained that because this request is handled by the operating system’s credential service, it never passes through Private Relay’s proxy, allowing the destination server to see the user’s true IP address.

During testing, the researchers built a website to demonstrate the vulnerability. 404 Media confirmed that the site could reveal the real IP address of users who had Private Relay enabled. The issue also impacts OnionBrowser, which uses Apple’s WebKit engine like all iOS browsers. While the Tor network is designed to anonymize traffic, the flaw can still expose users’ IP addresses in certain scenarios. The official Tor Browser from the Tor Project is not affected by this specific issue.

Apple has acknowledged the report and stated it is investigating the findings. The developers of OnionBrowser described the issue as “dire” but have not provided a timeline for a fix. This is the second recent privacy concern for Apple’s paid privacy features; last month, a bug in the Hide My Email feature was found to reveal users’ real email addresses, which Apple addressed after more than a year.

For those interested in broader privacy risks, a related case involved MI5 and police unlawfully accessing a journalist’s call data, resulting in damages and raising concerns about source protection. Details on that incident can be found in this report on unlawful access to journalist data.

Related articles