A flaw in Apple’s Private Relay feature can expose users’ real IP addresses despite the service being designed to hide them, security researchers revealed in August 2026.
Researchers Talal Haj Bakry and Tommy Mysk published a blog post detailing the vulnerabilities and set up a website where users can test whether their IP address is leaking. TechCrunch independently verified on Tuesday that the site was able to reveal a real IP address even with Private Relay active. The issue was first reported by 404 Media.
According to the researchers, the problem stems from three flaws in WebKit, Apple’s web browser engine, which underlies all browsers on iOS. Private Relay is an opt-in feature available exclusively to iCloud+ subscribers and only functions within Safari. Unlike a VPN, which masks a user’s IP address at the system level, Private Relay’s protections are limited to Safari browsing sessions.
Mysk and Haj Bakry chose not to report the vulnerabilities to Apple directly. Mysk explained in a post on X that “our past experience with Apple tells us that reporting this issue would involve months of delays, inconsistent communication, and in some cases, denying the issue’s impact entirely.” Apple did not respond to a request for comment.
The researchers also develop a private browser called Psylo, which they say includes mitigations that prevent IP address leaks for its users.
For iCloud+ subscribers who rely on Private Relay for privacy while browsing, the flaw suggests their IP addresses may not be as protected as expected. Users concerned about the issue can visit the researchers’ test website to check whether their address is being exposed.
Source: TechCrunch