/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Mysk: Apple's Private Relay tool can leak users' IP addresses due to issues in Apple's WebKit browser engine, also affecting OnionBrowser, a Tor browser for iOS

Researchers found a group of issues that mean Private Relay isn't actually protecting users' real IP addresses.

404 Media Joseph Cox

Context & Ripple Effects

The report follows Apple’s recent fix for a Hide My Email flaw that exposed real email addresses, extending a pattern in which privacy features can fail at the point where identifying data should be masked.

WebKit is central to the new finding and has previously been implicated in a browser attack that exposed passwords and email content. The effect on OnionBrowser shows that an engine-level weakness can reach beyond Apple’s own browser experience.

First-order effects

  • Private Relay users may have their real IP addresses exposed despite using Apple’s privacy service, while OnionBrowser users inherit the same risk through WebKit.
  • Apple faces a remediation problem spanning Private Relay and WebKit rather than a defect confined to one privacy feature.

Second-order effects

  • OnionBrowser must assess its protections against the reported WebKit behavior, because its users depend on a browser layer implicated in the IP exposure.
  • Apple’s privacy tools face closer scrutiny as the Private Relay report arrives soon after the company fixed the Hide My Email identity-exposure issue.

Third-order effects

  • Shared browser-engine dependencies concentrate privacy risk: a WebKit flaw can weaken protections in multiple apps that present different anonymity or privacy promises.
  • If this pattern persists, Apple’s privacy stack will be judged less on individual feature branding and more on whether its underlying components prevent identifier leakage across services.

The trend: Apple’s privacy products are increasingly being tested as an interconnected stack, where shared components can turn a single flaw into exposure across several protections.

Discussion

  • @psylo_app @psylo_app on x
    Security Bulletin: WebKit's handling of passkeys can cause iCloud Private Relay to leak your device's real IP address. The same behaviour affects all iOS browsers that rely on proxy connections to hide the device's IP, including Psylo, Onion Browser, and other proxy or Tor [video…
  • @mysk_co @mysk_co on x
    iCloud Private Relay can leak your IP due to issues with WebKit. This affects all iOS browsers that rely on proxy connections, including Psylo (Apple requires all iOS browsers to use WebKit). We just released Version 1.3.1 to address these issues. More details below👇:
  • @mysk_co @mysk_co on x
    It's only the device's IP address, some DNS requests, and system DNS server IPs that are leaked here. Nothing more. “User data” might imply that more data is exposed, such as the user's email or name. [image]
  • @evacide @evacide on bluesky
    Researchers find a flaw in Apple's Private Relay that exposes users' real IP addresses, which also affects users of Tor's OnionBrowser in iOS: www.404media.co/apples-priva...
  • @josephcox Joseph Cox on bluesky
    New from 404 Media: Apple's ‘Private Relay’ is exposing users' real IP addresses.  Private Relay is supposed to protect all your browsing in Safari.  But researchers found a bunch of issues that are exposing real IPs.  I verified they do.  Not fixed, a live issue  —  www.404media…
  • r/apple r on reddit
    Apple's ‘Private Relay’ Is Exposing Users' Real IP Addresses
  • @psylo_app @psylo_app on x
    Soon after we published the blog, we sent a link to the blog and demo website to Apple in a security report to make them aware of it. Now the report is already in the status “We're planning to address the issue you reported.” and a fix is planned for Fall 2026 🤯🤯🤯 [image]
  • @mysk_co @mysk_co on x
    It used to take months and months to reach this status. We got there in less than 24h
  • @onyxaudit @onyxaudit on x
    @ProtonVPN VPNs are not affected, since they tunnel the whole device at system level. (mysk) Two other traps. The “dire” quote is Mike Tigas talking about Onion Browser, not Apple. Apple's only on-record line is that it is investigating. (404media) And the test site 404 sent read…
  • @protonvpn @protonvpn on x
    July: Apple's “Hide My Email” leaks real emails. August: Apple's “Private Relay” leaks real user IPs. It's really starting to feel like privacy isn't Apple's strongest suit, despite the billions of dollars sunk into advertising it.
  • r/privacy r on reddit
    Apple's ‘Private Relay’ Is Exposing Users' Real IP Addresses