Apple's Private Relay Fails to Hide User IP Addresses in WebKit Flaw
Security researchers bypass Safari's privacy feature through browser engine vulnerabilities, raising questions about Apple's implementation choices

The Promise and the Problem
Apple's Private Relay arrived as part of the iCloud+ subscription bundle with a straightforward pitch: hide your IP address while browsing. For users willing to pay the premium tier fee, the feature promised a layer of anonymity when using Safari. Now, security researchers Talal Haj Bakry and Tommy Mysk have demonstrated that the protection can be bypassed entirely, exposing the very IP addresses Private Relay is meant to conceal.
The researchers published their findings this week alongside a public demonstration site where anyone can verify whether their IP address leaks through the feature. Independent testing confirmed the vulnerability works as described, successfully revealing actual IP addresses even with Private Relay enabled.
Three WebKit Weaknesses
The root cause lies within WebKit, Apple's browser engine that powers not just Safari but every browser running on iOS. According to the researchers, three separate features in WebKit create pathways for IP address exposure when exploited together.
At DailyTechWire, we've tracked Apple's browser engine policies across the region, and this incident underscores a persistent tension: by mandating WebKit for all iOS browsers, Apple creates a single point of failure. When WebKit has a privacy flaw, no alternative rendering engine can offer users an escape route on iPhones or iPads.
Private Relay operates exclusively within Safari and only for iCloud+ subscribers. Unlike a system-level VPN that routes all network traffic through encrypted tunnels, Private Relay applies its protections narrowly to Safari browsing sessions. This architectural choice means users who assume they have comprehensive IP masking may be operating under a false sense of security, particularly if they use Safari for sensitive browsing but other apps for different tasks.
Why the Researchers Went Public First
Mysk and Bakry made an unusual decision: they published their findings without first notifying Apple through a coordinated disclosure process. Mysk explained the choice publicly, citing previous interactions with Apple's security response team that involved extended delays, inconsistent communication, and outright dismissals of reported issues.
The researchers develop Psylo, a privacy-focused browser, and have already implemented mitigations within their own product to prevent the IP leak vector. Their decision to bypass Apple's bug reporting channels reflects growing frustration among independent security researchers who feel that large platform holders treat vulnerability reports as inconveniences rather than opportunities to protect users.
Apple has not yet issued a public statement on the findings or outlined a timeline for potential fixes.
Scope and Real-World Impact
The vulnerability affects anyone using Private Relay on Safari across iOS devices. Because WebKit underpins all iOS browsers, switching to Chrome or Firefox on an iPhone does not eliminate the underlying engine weaknesses, though those browsers do not offer Private Relay in the first place.
For threat modeling, the flaw matters most to users who rely on Private Relay to mask their location or identity from websites, advertisers, or network observers. Journalists, activists, or professionals handling sensitive research may have chosen Private Relay as a lightweight privacy tool without realizing its limitations. The public disclosure and working proof-of-concept site mean adversaries now have a straightforward method to unmask users.
At the same time, Private Relay was never marketed as a robust anonymity solution comparable to Tor or commercial VPNs. Apple positioned it as a privacy enhancement, not a security guarantee. Still, the gap between user expectations and actual protection creates risk, especially when users do not fully understand the scope of what Private Relay covers.
Architectural Trade-Offs in Consumer Privacy Tools
Private Relay's design reflects Apple's broader approach to privacy: build features into the platform, keep them simple, and avoid the complexity of full VPN configurations. This strategy works well for mainstream users who want one-click privacy boosts without managing server lists or encryption protocols.
The trade-off is resilience. A feature tightly integrated into a single browser on a single operating system inherits all the weaknesses of that environment. When WebKit has a flaw, Private Relay has a flaw. When Apple's update cycle is slow, users remain exposed.
Across Asia, where VPN usage is common for both privacy and content access, products like Private Relay occupy an awkward middle ground. They offer less protection than dedicated VPN services but come bundled with iCloud+ subscriptions that many users already pay for. The convenience factor drives adoption, but incidents like this IP leak remind users that convenience and security do not always align.
Next Steps for Users and Apple
For iCloud+ subscribers who rely on Private Relay, the immediate options are limited. Switching to a full VPN service provides system-wide IP masking and does not depend on WebKit's security. Users can also test their own exposure using the researchers' demonstration site, though doing so reveals their IP address to the researchers themselves.
Apple faces a credibility test. The company has built much of its brand identity around privacy, with high-profile campaigns emphasizing user protection. A WebKit flaw that undermines a paid privacy feature strikes at that narrative. How quickly Apple patches the issue and whether the company revises its vulnerability disclosure processes will signal how seriously it takes independent security research.
The researchers' decision to release their findings publicly, rather than through Apple's channels, may accelerate a fix or may provoke a defensive response. Either way, the episode illustrates the fragile nature of privacy features that rely on proprietary, closed ecosystems. When the ecosystem has a hole, users have few alternatives and limited visibility into when, or if, repairs will come.


