Apple’s Private Relay, a privacy feature designed to conceal users’ IP addresses while browsing with Safari, can be bypassed under certain conditions, allowing websites to identify a user’s real IP address, according to security researchers.
The researchers have published their findings and launched an online tool that lets users check whether their IP address is exposed despite having Private Relay enabled. Independent testing has confirmed that the issue can reveal a user’s actual IP address in some cases.
Follow THE FUTURE on LinkedIn, Facebook, Instagram, X and Telegram
Issue Linked To WebKit
According to researchers Talal Haj Bakry and Tommy Mysk, the vulnerability stems from three features within WebKit, Apple’s browser engine used across iOS browsers.
Unlike a traditional virtual private network (VPN), Private Relay protects browsing activity only within Safari and is available exclusively to iCloud+ subscribers. Because the feature operates at the browser level rather than across the entire operating system, its privacy protections are more limited than those offered by a VPN.
Researchers Bypass Apple’s Reporting Process
Rather than reporting the issue through Apple’s security programme, the researchers chose to disclose their findings publicly. Mysk said previous interactions with Apple had been marked by lengthy delays, inconsistent communication and disagreements over the significance of reported vulnerabilities, leading the team to publish the research directly.
Apple has not publicly commented on the findings. The researchers also said their own privacy-focused browser, Psylo, includes safeguards designed to prevent this type of IP address leakage.







