Apple’s Private Relay feature, designed to shield users’ real IP addresses while browsing Safari, contains security flaws that allow the hidden address to be exposed. Security researchers discovered that vulnerabilities in Apple’s WebKit browser engine can be exploited to circumvent the privacy protection, according to findings disclosed this week.
The researchers demonstrated their discovery by creating a test website where users can verify whether their actual IP address is visible despite having Private Relay enabled. When TechCrunch tested the site, the vulnerability successfully revealed the user’s real IP address. The issue stems from three specific technical weaknesses within WebKit, which powers all browsers on iOS devices.
Private Relay is available exclusively to iCloud+ subscribers and only functions within Safari, distinguishing it from traditional VPN services that offer system-wide protection. The researchers who uncovered the flaw opted not to report it directly to Apple, citing previous experiences with slow response times and communication difficulties from the company.
Apple has not yet commented on the security issue. Meanwhile, the researchers behind an alternative private browser called Psylo have announced they have implemented safeguards to prevent similar IP leaks for their users.