Your iCloud Private Relay Might Not Be Hiding Your IP Address After All

If you pay for iCloud+ and rely on Private Relay to keep your IP address away from prying websites, here's some news that's going to sting a little: it might not be working the way Apple promised.

Security researchers Tommy Mysk and Talal Haj Bakry just published findings showing that Private Relay can leak your real IP address to any website that supports (or simply pretends to support) passkeys. That's a big deal, since passkeys are everywhere now, quietly baked into login flows across the web.

So what's actually going wrong?

The researchers explain that when a passkey request happens, it's issued by the operating system's credential service rather than by Safari itself — which means it never actually goes through Private Relay's proxied path. Your device's real IP address gets sent to the destination server either way.

In plain English: Private Relay only protects traffic that flows through Safari. Passkey requests sneak out through a different, system-level channel, and that channel was never covered.

The kicker is that you'd have zero indication this is happening. There's no popup, no warning, nothing in your browser telling you your IP just slipped out the back door. It looks and feels like a normal passkey login the entire time.

It's not just Safari, either

Here's where it gets worse for iPhone and iPad owners. Because every browser on iOS is required to run on Apple's WebKit engine, the issue isn't limited to Safari — Chrome, Firefox, Edge, whatever you've got installed on your iPhone is built on the same underlying engine, so they're all exposed the same way.

Even more surprising, the researchers found the leak reaches into privacy-focused tools too. <cite index="3-1">OnionBrowser, an iOS app built for browsing through the Tor network, leaks real IP addresses the same way</cite>, which is a pretty rough outcome for an app whose entire purpose is anonymity.

Who's affected, and who isn't

If you use Private Relay as your main privacy tool on iPhone, iPad, or Mac, you're exposed. The good news, if there is any, is that <cite index="3-1">traditional system-wide VPNs aren't affected by this, because they encrypt your traffic at the operating system level instead of relying on an app-by-app proxy the way Private Relay does</cite>.

That's a meaningful distinction worth remembering: Private Relay was never a full VPN replacement, and this bug is a pretty clear demonstration of why.

What Apple has said

Apple's response so far has been muted. According to reporting from 404 Media,Mysk says the company was told about the issue, called it "dire" internally, but gave the researchers the go-ahead to disclose it publicly anyway. There's no fix timeline yet.

This also isn't the first time one of Apple's privacy features has quietly failed to do its job. Just last month, 404 Media reported that a bug in Hide My Email was actually revealing people's real email addresses, and Apple reportedly knew about that problem for more than a year before patching it. If that pattern holds here, don't expect a same-week fix.

Can you check if you're exposed?

Yes. Mysk and Haj Bakry built a test page that checks whether your device's real IP is leaking, even with Private Relay switched on. It's a quick way to see where you actually stand rather than just taking our word for it.

What you can do right now

Don't count on Private Relay alone if IP privacy really matters to you — pair it with, or switch to, a proper system-level VPN until this is patched. Turn off Private Relay for sensitive browsing if you'd rather not touch a third-party VPN, since an exposed IP with no protection at all is at least visible for what it is.

Watch for a Safari or iOS update addressing this — we'll update this piece as soon as Apple ships a fix.

Don't assume Tor apps have you covered on iOS right now, since the same underlying flaw applies there too.

We'll keep this page updated as more details come out, including if Apple gives any indication of when a patch is landing.