Many iPhone users pay for iCloud+, which includes Private Relay, and expect more privacy when browsing in Safari. New research shows that protection can break down. The Apple Private Relay IP leak stems from flaws in WebKit, the engine that powers browsers on iOS.
These WebKit features can send network traffic outside the configured proxy even when Private Relay is engaged. DNS prefetching can reveal a user's DNS path, while the other two features can expose the device's real IP address.
What's iCloud Private Relay?
iCloud Private Relay works like a built-in VPN for Safari, an Apple-developed browser. Private Relay hides a user’s IP address from websites and browsing activity from network providers. It primarily protects Safari, but also covers DNS queries and certain unencrypted app traffic.
Researchers Talal Haj Bakry and Tommy Mysk identified three WebKit features that send certain requests directly from the device rather than through the proxy. Private Relay can't mask the DNS or IP information associated with those requests.
How the IP Address Leakage Happens
The first issue involves DNS prefetching, a feature that's been around since iOS 26.0 and looks up website addresses before a user clicks a link. The lookup follows the device's usual DNS route instead of the proxy, which can expose the DNS servers connected to the user's actual network.
The second flaw affects WebAuthn Related Origin Requests, which are tied to passkey logins. During this process, the operating system's credential service retrieves a validation file without routing the request through the proxy. The feature that causes the request to expose the device's real IP address has been around since iOS 18.0.
The third issue involves WebTransport, a newer technology used for direct connections to servers. When WebTransport establishes an HTTP/3 connection, the traffic can travel outside the proxy and reveal the actual IP address of the user's device. The flaw has been around since the iOS 26.4 update.
Who Does This Leak Affect?
Safari isn't the only browser affected. Because iOS browsers rely on WebKit, these WebKit vulnerabilities can also create problems for Onion Browser and other proxy-based apps designed to prevent IP address leakage. The official desktop Tor Browser is unaffected because it does not use WebKit; iOS Tor apps such as Onion Browser may be affected.
The Importance of Reliable Network Traffic Protection for User Privacy
When core browser mechanisms operate outside the expected privacy path, the protection people paid for becomes unreliable. This is especially concerning for anyone using Private Relay to protect sensitive activity or their location.
Apple has acknowledged the issue and said it's investigating. Researchers noted that a full fix may take time, since these mechanisms are built into how WebKit handles connections at a fundamental level.
How Users Can Take Action Now
If you're worried about your business's private information being exposed through the Apple Private Relay IP leak, consider using a dedicated VPN. With a VPN, you can encrypt all of your device traffic, not just traffic from Apple's Safari browser. Because a VPN is separate from WebKit, it can provide a reasonable safeguard against flaws within the Apple Private Relay system.
