PSA: Apple’s Private Relay can leak your real IP address
Researchers have identified vulnerabilities in Apple's Private Relay, a Safari-exclusive privacy feature for iCloud+ subscribers designed to mask users' IP addresses. The flaws stem from three specific issues within Apple's WebKit browser engine, allowing attackers to circumvent the protection and expose users' real IP addresses despite the feature being active.
The security researchers chose not to report the issue directly to Apple, citing previous negative experiences with the company's response to vulnerability disclosures. Apple has not publicly addressed the matter, while the researchers have published a testing website for users to check if their IP leaks and developed their own private browser with mitigations against this type of vulnerability.
- Apple's Private Relay can be circumvented to reveal hidden IP addresses due to three flaws in the Safari engine WebKit
- Researchers published findings and a testing tool without reporting to Apple first, citing poor past communication
- The vulnerability affects Safari only and exposes a gap in the privacy protection system