Apple's iCloud Private Relay, marketed as a privacy tool that masks user browsing traffic, has been found to leak the real IP addresses of users under certain conditions. The discovery, published in a report titled 'Private Relay Isn, So Private After All, Can Leak Your IP Address', reveals that the two-hop relay system designed to anonymize traffic can inadvertently expose the user's original IP address to the first relay server.
How the Leak Works
Private Relay operates by splitting the DNS query and IP address into two separate encrypted streams. The first relay, which sees the user's IP address, is supposed to only know the user's location but not the destination. The second relay, which knows the destination, is supposed to have no knowledge of the user's identity. However, the researcher found that if the connection to the second relay fails or if the network is configured to force DNS through a specific path, the first relay can log the IP address and associate it with the user's browsing activity.
Implications for User Privacy
For users who subscribe to iCloud+ specifically for the privacy benefits of Private Relay, the leak undermines a key selling point. While Apple has not yet publicly acknowledged the issue, the vulnerability could expose browsing habits to internet service providers or third parties monitoring the first relay. Users who combine Private Relay with a VPN are especially at risk because the two services can conflict, breaking the anonymity chain.
Why This Matters
This flaw arrives at a time when consumer privacy tools are under increasing scrutiny. Private Relay is one of the few built-in protections for Safari users, and its failure to consistently mask IP addresses could erode trust in Apple's privacy commitments. The finding also highlights the complexity of implementing multi-hop anonymity systems, which must handle edge cases like network failures without compromising privacy. If Apple does not patch this, users may need to switch to third-party VPNs that offer more robust leak protection, potentially undermining Apple's ecosystem lock-in. The consequences extend beyond individual users: businesses that rely on Private Relay for employee privacy on corporate devices could face data exposure risks.



