Apple built its brand on the promise that its tools could shield users from the surveillance embedded in modern internet infrastructure — yet researchers have found that iCloud Private Relay, the company's flagship privacy feature, leaks the very IP addresses it was designed to conceal. A vulnerability in WebKit, the engine beneath Safari on both iOS and macOS, creates pathways that bypass the proxy architecture entirely, exposing hundreds of millions of users who believed their location and browsing activity were hidden. The gap between a privacy promise and its technical fulfillment is rarel
Apple's Private Relay Found Leaking Users' Real IP Addresses
The feature has been functioning as advertised only in appearance.
So Private Relay was supposed to hide your IP address. How does a feature designed for that end up leaking it?
WebKit, the engine that runs Safari, has gaps in how it handles certain types of requests. Websites can exploit those gaps to reach out and grab the real IP address directly, bypassing the proxy tunnels entirely.
But Apple controls WebKit. They built it. How does a vulnerability like that slip through?
Because privacy features are complex, and the interaction between different layers of a system—the browser, the proxy, the network stack—creates unexpected pathways. Testing catches some things. Others hide until someone looks at it from the right angle.
What does this mean for someone using Private Relay right now?
It means the protection they thought they had isn't there. Websites can see their real location. ISPs can see their real IP. The feature is working, but it's not working.
Can users fix this themselves?
Not really. They can turn off Private Relay, which removes the false sense of security. They can add a VPN on top, which adds another layer of trust they have to place somewhere else. Or they can wait for Apple to patch it.
Why does this matter beyond the technical fix?
Because Apple's entire brand in privacy rests on the idea that they do this better than everyone else. When a core feature fails silently, it raises questions about what else might be failing that we don't know about yet.
The Pulse
- Apple's iCloud Private Relay — meant to route traffic through dual proxies so no single party can link identity to browsing — has been silently failing its core mission due to WebKit flaws on iOS and macOS.
- The vulnerability is not a fringe edge case: it affects hundreds of millions of devices, meaning ISPs and websites have been able to see real IP addresses that users believed were masked.
- Researchers disclosed the flaw responsibly without publishing the specific exploit mechanism, buying Apple time to patch before attackers can weaponize the vulnerability.
- Apple's likely response — bundling a WebKit fix into a standard OS update — could leave users exposed for weeks or months depending on how quickly they update.
- In the interim, users face an uncomfortable choice: abandon Private Relay entirely, or stack on a third-party VPN that introduces its own set of trust questions.
- The silent nature of the failure — no interface warning, no visible signal — strikes at Apple's broader credibility as a company that positions privacy as a genuine differentiator rather than a marketing posture.
Apple built its brand on the promise that its tools could shield users from the surveillance embedded in modern internet infrastructure — yet researchers have found that iCloud Private Relay, the company's flagship privacy feature, leaks the very IP addresses it was designed to conceal. A vulnerability in WebKit, the engine beneath Safari on both iOS and macOS, creates pathways that bypass the proxy architecture entirely, exposing hundreds of millions of users who believed their location and browsing activity were hidden. The gap between a privacy promise and its technical fulfillment is rarely visible to the people who depend on it most, and this discovery is a quiet reminder that trust in technology must always be earned in implementation, not just in marketing.
Apple has spent years building a reputation around privacy, positioning iCloud Private Relay as proof that its ecosystem protects users where others exploit them. The feature routes traffic through two separate proxies — one Apple-controlled, one operated by a content delivery partner — so that neither can simultaneously know who a user is and what they are browsing. The architecture is sound in theory. In practice, it has not been working.
Researchers have discovered that WebKit, the browser engine powering Safari across iOS and macOS, contains vulnerabilities that allow websites to extract a user's real IP address even when Private Relay is active. The proxy layer is bypassed entirely. Any user who trusted the feature to hide their location and browsing patterns from ISPs and trackers was operating under a false assumption — and had no way of knowing it from the interface.
The researchers disclosed the flaw without publishing the specific technical mechanism, giving Apple room to patch before the vulnerability can be weaponized. But the existence of the flaw is now public, and the exposure is already real. Apple will almost certainly address it through a WebKit security update bundled into a routine OS release, though the timeline remains uncertain — potentially leaving users vulnerable for weeks or months.
Until a patch arrives, options are limited: drop Private Relay and lose its protections, or add a third-party VPN that comes with its own trust calculus. Neither is a satisfying answer for users who chose Apple's ecosystem precisely because they wanted privacy without complexity.
What lingers beyond the technical fix is a harder question. When a privacy feature fails silently — when the gap between promise and performance is invisible to the people depending on it — the damage is not just to one product. It is to the credibility of the claim that good intentions, without rigorous verification, are enough.
Apple markets iCloud Private Relay as a shield for its users—a feature that routes internet traffic through encrypted tunnels to hide real IP addresses from websites and internet service providers. The company has spent years positioning privacy as a core value, a differentiator in a market where data harvesting is the norm. But researchers have discovered a fundamental crack in that promise: WebKit, the browser engine that powers Safari on iOS and macOS, contains vulnerabilities that allow websites to unmask users' actual IP addresses even when Private Relay is active.
The flaw is not a minor edge case. It strikes at the heart of what Private Relay is supposed to do. When a user enables the feature, Apple's system is meant to route their traffic through two separate proxies operated by different entities—one controlled by Apple, one by a content delivery network partner—so that neither party can see both the user's identity and their browsing activity simultaneously. The architecture is sound in theory. In practice, WebKit's implementation contains pathways that leak the real IP address directly to websites, bypassing the proxy layer entirely.
This is not the first time Apple's privacy tools have encountered problems in the field. The company has built a reputation on privacy commitments, from on-device processing to encrypted messaging. But the gap between marketing and implementation has narrowed before. What makes this discovery significant is the scope: the vulnerability affects both iOS and macOS, meaning it touches hundreds of millions of devices. Any user who believed Private Relay was protecting their location and browsing patterns from ISPs and trackers was operating under a false assumption.
The researchers who uncovered the issue did not disclose the specific technical mechanism in detail—a responsible approach that gives Apple time to patch before attackers can weaponize the flaw. But the existence of the vulnerability is now public knowledge, and the implications are immediate. Users who rely on Private Relay for privacy have been exposed. Websites and ISPs that users thought could not see their real IP addresses have been able to see them all along. The feature has been functioning as advertised only in appearance.
Apple's response will likely involve security patches for WebKit, but the timeline is uncertain. The company typically bundles security fixes into regular OS updates, which means some users may remain vulnerable for weeks or months depending on when they update their devices. In the interim, anyone concerned about IP address leakage has limited options: disable Private Relay and accept the loss of that protection, or layer on additional privacy tools like a third-party VPN service, which introduces its own trust considerations.
The discovery also raises a broader question about the relationship between privacy claims and actual privacy. Apple has built significant brand value on the assertion that it protects user data better than competitors. When a core privacy feature fails silently—when users cannot tell from the interface that their IP addresses are being leaked—the company's credibility takes a hit that extends beyond this single vulnerability. It suggests that privacy features require not just good intentions but rigorous testing and transparency about limitations.
For now, the story is one of waiting. Apple will patch the WebKit vulnerabilities. Users will update their devices. The feature will continue to exist, and most users will likely continue to use it, perhaps without ever learning that it failed to do what it promised. But the moment of discovery has already happened, and it serves as a reminder that privacy in technology is often more fragile than the marketing suggests.