Apple users who use iCloud Private Relay to hide their IP address could be at risk. According to a report by 404 Media, security researchers have discovered a weakness that allows some websites to still determine a user’s real IP address, even when Private Relay is enabled. That’s because of how Apple’s browser handles passkeys, allowing some requests to bypass the privacy guard. The same problem also affects OnionBrowser on iOS, raising concerns for users who rely on it for anonymous browsing. Apple has acknowledged the report and says it is investigating the findings shared by the researchers. Here is everything we know so far about Apple’s iCloud Private Relay IP masking issue.
The issue was discovered by security researchers Tommy Mysk and Talal Haj Bakry, who say that any website supporting, or even pretending to support, passkeys can identify a Private Relay user’s real IP address. The researchers have also created a website that allows users to test whether their real IP address is also exposed with iCloud Private Relay enabled. In 404 Media’s own testing, the tool successfully revealed the real IP address of a user who had Private Relay enabled.
Private Relay is a feature that is available as part of Apple’s paid iCloud+ subscription and is meant to hide a user’s IP address and browsing activity from websites and internet providers while using Safari. However, unlike a traditional VPN, Private Relay only protects Safari traffic and does not cover all internet activity on a device.
According to the researchers, the problem starts with passkeys, which are designed as a safer alternative to passwords. When a website requests a passkey, part of the process is handled by iOS instead of Safari. Because this request does not travel through Private Relay, the website receives the device’s actual IP address instead of the masked one. The researchers also identified two related WebKit leaks notably the DNS prefetching (added in iOS 26) can reveal a user’s real DNS servers, and WebTransport (added in iOS 26.4) can also expose a real IP address.
The researchers also found that the same behaviour affects OnionBrowser because all browsers on iOS must use Apple’s WebKit engine. However, they said the issue does not affect the official Tor Browser available from the Tor Project on supported platforms.
Also read: OpenAI asks court to throw out Apple trade secrets lawsuit, says iPhone maker is masking AI failures
While Apple has not publicly commented on the recently discovered issues with IP address masking in iCloud Private Relay, 404 Media reported that the company has acknowledged the findings and said it is investigating the researchers’ claims.
According to Mysk, Apple privately described the issue as ‘dire’ when he reported it, though the company did not give a public timeline at the time of disclosure. A later update from 9to5Mac notes that Apple’s security report status now indicates a fix is ‘planned for Fall 2026’, though no exact date has been confirmed.