Briev
Live
Technology

Researchers expose flaw that lets Apple Private Relay reveal real IP addresses

A security study shows that Apple’s Private Relay can be bypassed, allowing a user’s actual IP address to be exposed while browsing Safari.

A pair of security analysts discovered that Apple’s Private Relay, an optional feature for iCloud+ users meant to mask IP addresses in Safari, can be circumvented due to three flaws in the WebKit engine used across iOS browsers. Their findings were detailed in a blog post and accompanied by a public website that checks whether a device’s real IP is being leaked; one outlet verified the site’s ability to expose its own address.

The vulnerability was initially flagged by one outlet, and the researchers explained they did not report it to Apple because of previous experiences with slow or dismissive responses. Private Relay operates only within Safari and does not function like a full-system VPN. The investigators also develop the Psylo private browser, which now includes protections against the identified leak. Apple has not responded to requests for comment.

Why it matters

Users relying on Private Relay may think their location is hidden, but the flaw can expose their real IP, affecting privacy.

In this story

Apple Private RelayIP address leakWebKitiCloud+ subscribersSafari browsersecurity researchersprivacy flawPsylo browser