Apple’s iCloud Private Relay can expose users’ real IP addresses, security researchers reported after building tests that returned unmasked IPs to destination sites.
The leaks are caused by three WebKit flaws that allow certain operating-system-level requests to bypass Private Relay’s proxy path, including requests triggered by passkeys via WebAuthn.
“In short: any website that supports, or pretends to support, passkeys can see the user’s real IP address despite having iCloud Private Relay on,” Tommy Mysk, one of the researchers, told 404 Media.
Because all iOS browsers must use Apple’s WebKit engine, the researchers found the issues affect at least one Tor client on iOS, with OnionBrowser showing exposure while the official Tor Browser is not impacted, the report says.
The researchers developed a site to demonstrate the problem and said it returned real IP addresses in 404 Media’s tests.
Private Relay is offered as part of iCloud+ and is not a true virtual private network, routing only Safari traffic rather than all device network activity.
Apple told 404 Media it is investigating the report, and the researchers disclosed the WebKit flaws on August 4.