Apple’s Private Relay feature could reveal your IP address to websites and services

← Back to the feed

Apple’s Private Relay feature could reveal your IP address to websites and services

Engadget · 2 hours ago

Security researchers have found that Apple's Private Relay, a feature meant to hide users' IP addresses while browsing in Safari, can fail to do so because of a flaw in WebKit, Apple's browser engine. The issue arises specifically with passkeys, an increasingly popular passwordless login method, because authentication requests made via passkeys occur outside the browser itself, beyond the scope of Private Relay's protection. This matters because it undermines a core privacy promise of an iCloud+ feature that users may rely on to keep their identity and location hidden from websites and services.

The problem is not limited to Safari, as the underlying WebKit flaw affects all iOS browsers, meaning IP addresses could also be exposed when using passkeys in privacy-focused browsers such as Onion Browser and the researchers' own Psylo browser. Researchers Talal Haj Bakry and Tommy Mysk say they have alerted Onion Browser and the Tor Project, and Apple has confirmed it is investigating, though the researchers caution that a fix could take a long time, citing a similar Hide My Email leak that took Apple roughly a year to resolve after it was first reported.

  • Private Relay can leak IP addresses due to a WebKit flaw
  • Passkey logins bypass Private Relay's browser-based protection
  • Fix could take a long time, based on Apple's past track record

New here? Start with this

Private Relay is a paid iCloud+ feature that hides a user's IP address from websites when browsing in Safari, essentially masking where someone is connecting from and helping to prevent tracking based on location or network identity. It works by routing traffic through Apple's own relay system rather than sending it straight to the site being visited. Security researchers have now found circumstances in which this protection does not hold.

Passkeys are a newer way of logging into accounts without typing a password, using a device's built-in security instead. Because the checks involved in a passkey login happen at a different level of the phone's software than normal browsing traffic, they can bypass Private Relay entirely, meaning a real IP address may still reach a website. This matters because people who use Private Relay generally do so specifically to keep this kind of information private, and the flaw sits in Apple's underlying WebKit browser engine, so it is not confined to Safari alone.

The findings come from researchers Talal Haj Bakry and Tommy Mysk, and Apple has said it is looking into the issue. Similar privacy-focused apps that rely on the same underlying engine, including Onion Browser and the Tor Project's tools, can be affected in the same way, which is why those groups have also been informed.

Research Science

Read the full article at the source →