Apple’s Private Relay Feature Could Reveal Your IP Address To Websites And Services


It’s supposed to mask your IP address, but researchers found that it doesn’t always work due to a WebKit issue.

Apple’s Private Relay feature is supposed to ensure that no website or even the company itself can see your IP address when you browse the web on Safari. But according to security researchers Talal Haj Bakry and Tommy Mysk, it doesn’t always work as intended due to issues with Apple’s web browser engine, WebKit. 

One of the issues they found is related to passkeys, which are gaining ground as a new secure and password-free login method. As 404Media explains, when you use a passkey to log in, your device makes an authentication request outside of the browser itself. Private Relay is an iCloud+ feature bound to Safari and doesn’t shield your identity throughout your device like a real VPN does. So, if you log into a website or a service with your passkey on Safari, it could leak your IP. 

The possibility of an IP leak isn’t confined to Safari either. Since the issue lies with WebKit that’s used on all iOS browsers, your IP could also become visible to websites and services if you use passkeys on other browsers designed for privacy and anonymity, like OnionBrowser and the researchers’ own Psylo browser. 

The researchers said in a post on X that they have already contacted OnionBrowser and the Tor Project, which provides the anonymity network the browser uses, to share their findings and solutions. Apple told 404Media that it’s already investigating the researchers’ report, but as the researchers said in their post, it could take a lot of time before the company addresses the problem. They mentioned the issue with iCloud’s Hide My Email, for instance, which another research team discovered in mid-2025. Apple didn’t roll out a fix, which would prevent the feature from leaking the real email addresses behind aliases, until a year later. 



Source link

  • Related Posts

    OpenAI’s Agents Reportedly Shared Exploits With Each Other Through A Messaging Board

    OpenAI’s agents had apparently shown unusual behavior way before the attack on Hugging Face happened. At the Black Hat USA security conference in Las Vegas, two OpenAI employees revealed more details…

    Linux Use Skyrockets to a Historic High

    Linux, a free, open-source operating system, runs most of the internet’s servers, yet it remains a niche choice on consumer PCs. For years, Linux’s desktop market share in North America…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    EXCLUSIVE: Key members of India’s Bishnoi gang named in Canadian intelligence report

    EXCLUSIVE: Key members of India’s Bishnoi gang named in Canadian intelligence report

    Jeffrey Epstein investigation: New Mexico sues DOJ, Todd Blanche for blocking state probe

    Jeffrey Epstein investigation: New Mexico sues DOJ, Todd Blanche for blocking state probe

    OpenAI’s Agents Reportedly Shared Exploits With Each Other Through A Messaging Board

    OpenAI’s Agents Reportedly Shared Exploits With Each Other Through A Messaging Board

    Transfer rumors, news: Liverpool offered Real Madrid CB amid defensive woes

    Transfer rumors, news: Liverpool offered Real Madrid CB amid defensive woes

    Can you play Big Walk alone or with randoms?

    Can you play Big Walk alone or with randoms?

    10 Summer-Proof Makeup Products that Best Dancing and Dining

    10 Summer-Proof Makeup Products that Best Dancing and Dining