Researchers find iCloud Private Relay leaks real IP addresses on Safari

Researchers Talal Haj Bakry and Tommy Mysk discovered that iCloud Private Relay, a privacy feature for Safari on iOS and macOS, can be bypassed by DNS prefetching, WebAuthn, and WebTransport. These legitimate browser technologies can expose users' real IP addresses to websites, undermining the feature's purpose. The findings affect iCloud+ subscribers who use Private Relay. The researchers recommend keeping devices updated and suggest users may disable these features in Safari settings. Apple has not yet responded, but updates are expected to address the loopholes.

Researchers find iCloud Private Relay leaks real IP addresses on Safari
1 source
Published Aug 16, 2026

Topic overview

Briefly

  • Researchers found DNS prefetching, WebAuthn, and WebTransport can bypass Safari's proxy.
  • These leaks expose real IP addresses to websites despite Private Relay being enabled.
  • Users are advised to keep devices updated and consider disabling these features.

What happened

Researchers Talal Haj Bakry and Tommy Mysk have identified three legitimate browser technologies that can bypass Apple's iCloud Private Relay, a privacy feature designed to hide users' real IP addresses and locations when browsing in Safari. The vulnerabilities affect iCloud+ subscribers who enable Private Relay on iOS and macOS devices. The first issue involves DNS prefetching, a standard browser optimization that resolves domain names before a user clicks a link. In Safari, this prefetching can occur outside the proxy, allowing websites to see DNS requests from the user's real network. The second issue is related to WebAuthn, the web standard used for passkeys. When a user authenticates with a passkey, the request may be sent directly from the device rather than through the proxy, exposing the IP address. The third issue involves WebTransport, a modern protocol for real-time communication. WebKit can establish a WebTransport connection directly from the device, bypassing the proxy configuration. These findings are concerning because they exploit standard web technologies, not malicious code. The researchers demonstrated that a website could potentially learn a user's real IP address or DNS information, undermining the privacy protection that Private Relay is supposed to provide. The impact is most significant for users who rely on Private Relay specifically to prevent websites from seeing their IP address. However, the researchers advise against panic or immediately disabling the feature. Instead, they recommend keeping Apple devices updated with the latest iOS, iPadOS, and macOS updates, as Apple may address these loopholes in future releases. Users can also disable DNS prefetching, WebAuthn, and WebTransport in Safari settings, though this may affect functionality. The findings highlight the ongoing challenge of balancing privacy with the convenience of modern web features. While Private Relay is not a complete privacy solution, it still offers a layer of protection for many users. The researchers suggest that users should be aware of these limitations and consider additional privacy measures, such as using a VPN, if they require stronger anonymity. Apple has not yet publicly responded to these findings, but the company is likely to work on patching the vulnerabilities in upcoming software updates. Until then, users who are particularly concerned about their IP address being exposed may want to adjust their Safari settings or use alternative privacy tools.

Comprehensive report

Full story,
in detail.

Trace the developments that led here, see how the story evolved, and understand the forces and wider context surrounding it.

Entities

How Mestios works We aggregate coverage, extract key information, and use AI to summarize and compare perspectives. Learn more

Updated Aug 16, 2026

AI-generated summary. Please verify important information from original sources.