Yes, iCloud Private Relay Can Leak Your Real IP
The iCloud Private Relay leak is a WebKit security vulnerability in Apple’s browser engine that allows certain website features, especially during passkey authentication, to bypass Safari’s privacy protections and expose a user’s real IP address and DNS information, even when iCloud Private Relay or proxy-based privacy browsers are enabled.
If you thought iCloud Private Relay made your iPhone or Mac “safe by default,” this flaw proves otherwise. Security researchers have found that multiple WebKit features can sidestep application-level proxies and reveal your network details, meaning websites can still see where you are connecting from despite Apple’s privacy branding. In plain terms, your IP address exposed on iPhone is not a theoretical edge case; it is happening at the exact moment you expect the most protection—when you sign in with passkeys.
For users who bought into Apple’s privacy promises, this is an Apple privacy flaw that directly undercuts one of the company’s flagship subscription features. If you care about anonymity and tracking resistance, you need to adjust how you browse and authenticate right now.
How WebKit Lets Passkey Logins Bypass Your Privacy
Under the hood, this iCloud Private Relay leak is driven by three WebKit features that bypass application-level proxy settings: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. Each one cuts around the protections you assume are in place. DNS prefetching resolves hostnames using your normal DNS path, revealing your real DNS servers to whoever is watching the lookups. WebTransport opens direct HTTP/3 connections from your device, bypassing proxies entirely and sending traffic straight to a server.
The most dangerous element for everyday users is the passkey authentication bypass. The vulnerability centers on how WebAuthn requests interact with iOS and macOS: when a site prompts for a passkey—or even pretends to support one—the related network request is handled by Apple’s system-level credential service instead of Safari’s browser stack. A webpage can trigger a WebAuthn Related Origin Request that this credential service fetches directly, so the destination server receives your real IP address.
You see a familiar passkey sheet and assume you are protected, but behind that friendly UI, your real IP address and DNS data are exposed during passkey authentication on affected devices. Websites do not need to show a visible prompt; these checks can happen quietly in the background. That is why this WebKit security vulnerability is so insidious: it abuses the very mechanism designed to make logins safer.

Who Is Affected: It’s Bigger Than Safari
This is not “a Safari bug.” Because Apple requires every iOS browser to use WebKit, alternative browsers share the same exposure. Three recently discovered WebKit privacy leaks expose users’ real IP addresses on iPhone and Mac, even when they use a proxy browser or iCloud Private Relay. That includes privacy-focused apps and Tor-style browsers that depend on application-level proxies.
Researchers have shown that the flaw leaks real IP addresses even on privacy-focused apps like Onion Browser on the Tor network. Proxy-based privacy browsers such as Psylo and Onion Browser are affected because WebKit’s DNS prefetching, WebAuthn, and WebTransport features can bypass their proxy settings. You can use the strictest browser settings and still lose if the underlying engine routes traffic outside the proxy.
The practical impact is clear: iPhone and Mac users relying on Private Relay for privacy are at risk when signing into accounts with passkeys. A test website built by the researchers has already confirmed that it can reveal an IP address iCloud Private Relay should have concealed. In other words, many websites may already have collected this data.

How Serious Is This Apple Privacy Flaw?
This is not the kind of bug you shrug off. A new report has shown how attackers can learn a Private Relay user’s real IP address, and many websites may already have collected the information. The leak hits the exact crossover of identity (your passkey account) and location (your IP), making it a powerful tracking point whenever you authenticate.
Worse, the behavior has been present since iOS 18 for WebAuthn Related Origin Requests, with DNS prefetching and WebTransport leaks arriving in later iOS versions. That means this is not a one-off regression but a privacy blind spot built into newer WebKit features. For users, the risk is that sign-in events that should be privacy-preserving become a fingerprint, tying your account to your home or office network.
Apple has acknowledged the report and says it is investigating. After the findings were submitted, Apple updated the report’s status to indicate it plans to address the issue, with a fix scheduled for fall 2026. Until that arrives on both iOS and macOS, the WebKit privacy leak remains an active concern that you must defend against yourself.
Stay Protected: Concrete Steps You Should Take Now
The uncomfortable truth: privacy browsers alone do not protect against this vulnerability without fixes to the underlying WebKit code. If you keep using passkeys behind iCloud Private Relay with no extra measures, you are gambling with your IP address. You need to add independent layers that WebKit cannot bypass.
- Use a reputable system-wide VPN on your iPhone and Mac. Traditional VPNs remain unaffected because they encrypt traffic at the OS level, so WebKit cannot route around them.
- Combine that VPN with strict browser privacy settings, disabling features like WebAuthn, DNS prefetching, and WebTransport where your browser allows. This creates multiple security layers, with the VPN blocking these leaks entirely.
- Limit passkey use on sensitive accounts until updates ship. Where possible, use app-based two-factor authentication or security keys alongside passwords instead of relying exclusively on passkeys.
- Monitor logins and account activity, especially for services you access frequently with passkeys. Treat unexpected sign-in alerts as signals that your IP-based profile may already be in circulation.
- Test whether you are affected by visiting the proof-of-concept website created by the researchers, which detects all three leaks.
Apple needs to address this WebKit security vulnerability in future iOS and macOS updates, but users cannot wait passively. If you rely on iCloud Private Relay, treat it as one layer, not a shield. Add a VPN, harden your browser, and treat passkey logins as potential exposure points until Apple’s promised fix arrives.






