Mysk: Apple's Private Relay tool can leak users' IP addresses due to issues in Apple's WebKit browser engine, also affecting OnionBrowser, a Tor browser for iOS
Researchers found a group of issues that mean Private Relay isn't actually protecting users' real IP addresses.
Private Relay users may have their real IP addresses exposed despite using Apple’s privacy service, while OnionBrowser users inherit the same risk through WebKit.
Apple faces a remediation problem spanning Private Relay and WebKit rather than a defect confined to one privacy feature.
Second-order effects
OnionBrowser must assess its protections against the reported WebKit behavior, because its users depend on a browser layer implicated in the IP exposure.
Apple’s privacy tools face closer scrutiny as the Private Relay report arrives soon after the company fixed the Hide My Email identity-exposure issue.
Third-order effects
Shared browser-engine dependencies concentrate privacy risk: a WebKit flaw can weaken protections in multiple apps that present different anonymity or privacy promises.
If this pattern persists, Apple’s privacy stack will be judged less on individual feature branding and more on whether its underlying components prevent identifier leakage across services.
The trend: Apple’s privacy products are increasingly being tested as an interconnected stack, where shared components can turn a single flaw into exposure across several protections.
Security Bulletin: WebKit's handling of passkeys can cause iCloud Private Relay to leak your device's real IP address. The same behaviour affects all iOS browsers that rely on proxy connections to hide the device's IP, including Psylo, Onion Browser, and other proxy or Tor [video…
iCloud Private Relay can leak your IP due to issues with WebKit. This affects all iOS browsers that rely on proxy connections, including Psylo (Apple requires all iOS browsers to use WebKit). We just released Version 1.3.1 to address these issues. More details below👇:
It's only the device's IP address, some DNS requests, and system DNS server IPs that are leaked here. Nothing more. “User data” might imply that more data is exposed, such as the user's email or name. [image]
Researchers find a flaw in Apple's Private Relay that exposes users' real IP addresses, which also affects users of Tor's OnionBrowser in iOS: www.404media.co/apples-priva...
New from 404 Media: Apple's ‘Private Relay’ is exposing users' real IP addresses. Private Relay is supposed to protect all your browsing in Safari. But researchers found a bunch of issues that are exposing real IPs. I verified they do. Not fixed, a live issue — www.404media…
Soon after we published the blog, we sent a link to the blog and demo website to Apple in a security report to make them aware of it. Now the report is already in the status “We're planning to address the issue you reported.” and a fix is planned for Fall 2026 🤯🤯🤯 [image]
@ProtonVPN VPNs are not affected, since they tunnel the whole device at system level. (mysk) Two other traps. The “dire” quote is Mike Tigas talking about Onion Browser, not Apple. Apple's only on-record line is that it is investigating. (404media) And the test site 404 sent read…
July: Apple's “Hide My Email” leaks real emails. August: Apple's “Private Relay” leaks real user IPs. It's really starting to feel like privacy isn't Apple's strongest suit, despite the billions of dollars sunk into advertising it.