Apple's celebrated privacy feature for protecting user location data and online activity contains a significant vulnerability that undermines its core purpose, according to researchers who discovered that the iCloud+ Private Relay system inadvertently leaks Internet Protocol addresses to websites despite users' expectation of anonymity.
The weakness exists within WebKit, the browser engine that Apple mandates all iOS browsers including Safari must utilise. Cybersecurity researchers Talal Haj Bakry and Tommy Mysk identified three separate flaws within this foundational technology that trigger what experts call DNS leaks—situations where a device's actual location identifier becomes visible online. The discovery, unveiled in early August, affects not only Apple's own privacy offering but extends to alternative browsers like Tor on iOS and Psylo, a privacy-focused browser the researchers themselves developed.
The vulnerability came to light when Psylo users reported experiencing DNS leaks on certain websites. Upon investigation, Haj Bakry and Mysk traced the problem to deeper architectural issues within WebKit itself. Because Apple's App Store policies require every iOS browser to utilise this single engine, the researchers note that the security vulnerability cascades across the entire iOS ecosystem. Their findings mean that privacy-conscious users—whether relying on Apple's built-in solutions or third-party alternatives—face unexpected exposure of their digital footprint.
Particularly troubling is that the flaw in Private Relay stems ironically from another security measure. The service, introduced in 2021 as a premium feature for iCloud+ subscribers, employs a two-relay system designed to ensure neither Apple nor any external party can simultaneously observe a user's identity and their browsing destinations. This architecture represents genuine innovation in consumer privacy technology. However, the actual vulnerability emerges when users authenticate using passkeys—a newer, more secure alternative to traditional passwords that major technology companies have promoted as password replacements.
Passkeys function by requiring the device to send authentication requests directly, outside the normal browser pathway. This architectural necessity means these requests completely circumvent Private Relay's protections, leaving the user's IP address fully exposed. The irony is substantial: by adopting a more secure authentication method, users inadvertently disable their privacy protections. This represents a fundamental design conflict that Apple has not yet publicly addressed.
IP addresses function as digital home addresses on the internet, uniquely identifying each connected device. Beyond their technical role in routing data, IP addresses reveal substantial personal information. They expose approximate geographic location down to postal code level, enabling internet service providers, website operators, and advertisers to build detailed profiles of user behaviour and movements. This information becomes particularly sensitive in Malaysia and Southeast Asia, where online privacy concerns intersect with government surveillance capabilities and the growing sophistication of commercial data harvesting operations.
Malicious actors have learnt to weaponise IP address information for targeted cyberattacks, making the exposure particularly concerning for businesses and individuals with elevated security needs. The ability to mask one's IP address has become a fundamental privacy safeguard that users increasingly expect from paid privacy services.
Apple has extensively marketed itself as the technology company most committed to user privacy. The firm spent considerable marketing effort in June promoting Safari's privacy advantages over competitors like Google Chrome, positioning itself as the conscientious alternative in the technology industry. Beginning in 2017 with Intelligent Tracking Prevention, Apple introduced technologies intended to block trackers from monitoring users. Private Relay represented the evolution of this philosophy into a paid premium service for iCloud+ customers, offering substantially stronger protections than these earlier features.
The Private Relay vulnerability highlights a critical distinction that many users fail to understand. Apple's Private Browsing feature, sometimes confused with Private Relay, operates at an entirely different level. Private Browsing simply prevents the browser from storing tabs, history, or browsing data locally—it provides no network-level privacy protections whatsoever. By contrast, Private Relay was explicitly designed to obscure users' activities from ISPs, website operators, and Apple itself. The distinction matters significantly for consumers paying for privacy they may not actually possess.
The researchers have taken steps to mitigate the issues within their own applications, updating Psylo and notifying the Tor Project and Onion Browser developers of the findings so that these privacy-focused tools can implement protective measures. However, the core vulnerability persists in WebKit itself, beyond the reach of individual application developers given Apple's monopolistic control over browser engines on iOS.
Apple has not publicly responded to requests for comment regarding the vulnerability, maintaining silence as the research circulates through technology and security communities. For Malaysian users accustomed to trusting Apple's privacy claims, the discovery presents a sobering reality: premium privacy features may contain unexpected gaps, and users cannot assume that paying for privacy guarantees actual protection. The situation underscores why independent security auditing of technology products remains essential, particularly as Southeast Asian governments increasingly scrutinise both user data and corporate privacy claims.
