Apple's iCloud Private Relay, a feature designed to mask users' browsing activity, has been found to leak real IP addresses through three WebKit mechanisms. The discovery by security researchers Talal Haj Bakry and Tommy Mysk reveals that DNS prefetching, WebAuthn Related Origin Requests and WebTransport circumvent application-level proxy settings, exposing user identities.
The Three WebKit Features Behind the Leak
Security researchers Talal Haj Bakry and Tommy Mysk identified three specific WebKit features that bypass application-level proxy settings. Each feature operates at a different layer of the browser's networking stack, collectively undermining the protections of Private Relay.
Why This Matters
This vulnerability directly undermines the core promise of Private Relay, a service that Apple markets as a privacy tool for iCloud+ subscribers. The leak exposes users to tracking by websites, advertisers and potentially malicious actors who can correlate IP addresses with browsing behavior. The impact is amplified on iOS, where Apple requires all browsers to use the same WebKit engine, making the flaw universal across Safari, Chrome and Firefox on iPhones.
The discovery also raises questions about Apple's security review process. The three features have been part of WebKit for years, suggesting that the proxy bypass has existed since Private Relay launched in 2021. Users who pay for the service have been operating under a false sense of privacy.
What Apple Must Address
Apple, however, has not commented publicly on the findings or provided a timeline for a fix. The company typically patches vulnerabilities through Safari updates, but the complexity of the issue may require changes to WebKit itself. Researchers recommend that users disable Private Relay until a patch is issued, or use a VPN that operates at the system level rather than the application level.
The broader lesson for the industry is that privacy features built on top of existing browser engines can be fragile. Until Apple revises WebKit to enforce proxy settings at a lower level, similar bypasses may remain possible. The incident serves as a reminder that no privacy tool is foolproof, especially when the underlying platform has design trade-offs that prioritize performance over security.



