Apple’s iCloud Private Relay should protect web traffic, but a new vulnerability means not all browsing is private.
Apple’s iCloud Private Relay feature is designed to obscure your web traffic so sites like advertisers, unscrupulous governments or malicious attackers can’t trace that traffic back to you. But it turns out the mechanism isn’t actually as private as Apple says.
, security researchers at software company Mysk discovered that even with iCloud Private Relay active, the IP address of a device or home network can be transmitted, which could be used to reveal a person’s identity or location.
is a feature for paid customers of Apple’s iCloud Plus service. It routes web traffic through proxy servers, obscuring your IP address and the website address you’re visiting, so neither the site nor Apple can see that information.
It’s also a feature that runs within Apple’s WebKit framework, which includes the Safari browser and other apps and services that use WebKit to access websites. It’s specifically
(Virtual Private Network), which encrypts all internet traffic and runs it through a proxy server.
r your connection is vulnerable. When I tested it using an iPhone 17 Pro and a MacBook Pro with iCloud Private Relay enabled, it correctly identified the IP address of my home internet router.
The information in the red box shows the IP address of my home router.
, the researchers noted that they chose to make the vulnerability public rather than report it to Apple first.
“Unfortunately, our past experience with Apple tells us that reporting this issue would involve months of delays, inconsistent communication, and in some cases, denying the issue’s impact entirely,” the researchers wrote. “We weren’t willing to wait months, or upwards of a year, sitting on bugs that undermine the core privacy guarantees of [Mysk’s browser] Psylo and iOS Tor browsers while saying or doing nothing.”
An Apple representative didn’t immediately respond to a request for comment.
, the method of signing into sites that’s more secure and user-friendly than usernames and passwords. WebKit bypasses the Private Relay proxy and sends requested information directly from the device.
“Because the fetch is issued by the operating system’s credential service rather than by Safari, it never enters Private Relay’s proxied path,” the researchers wrote on the
. “The destination server sees the device’s real IP address either way.”
There are two other paths that can reveal your IP address even with iCloud Private Relay enabled.
DNS prefetching is a way for websites to request data before it’s needed to speed up the connection. That happens separate from the relay mechanism, so the data is passed directly from your network to the website. However, a site must include the code in its HTML to trigger it.
The third vulnerability is with a low-latency method called WebTransport where WebKit opens a direct connection that bypasses the private relay and sends the user’s real IP address.
Apple’s security also took a hit recently when a bug in Apple’s iCloud
feature seemed to expose people’s real email addresses. It, too, is a paid feature of iCloud Plus and is now the focus of a
accusing Apple of false advertising, fraud and breach of contract.
Jeff Carlson writes about mobile technology at CNET, from cellular phone plans to devices and emerging technology.
Apple’s Private Relay Isn’t So Private After All, Can Leak Your IP Address
T-Mobile Is Stretching Its Device Commitment to 3 Years with New Installment and ‘2.0’ Phone Plans
Caught Up in T-Mobile’s Recent Outage? You Could Snag a Credit… If You Ask for It