Private Relay’s Promise—and the New Hole in Its Armor
The iCloud Private Relay leak is a newly disclosed WebKit security flaw in iOS where passkey-based authentication requests bypass Private Relay’s Safari-only protection, allowing websites to see and log a user’s real IP address even when Private Relay is enabled and expected to hide it.
If you rely on iCloud Private Relay to hide your location, your threat model needs an urgent update. Researchers have found that during passkey sign-ins, your IP address exposed on iPhone traffic never touches Private Relay’s masking path. In plain terms: a website can silently learn where you are while you think you are protected. This is not a theoretical corner case; any site that supports or pretends to support passkeys can trigger it. Apple has confirmed it is investigating the report and has not yet shipped a fix. Until that changes, treating Private Relay like a full privacy shield is wishful thinking.
How the WebKit Security Flaw Exposes Your Real IP
This passkey authentication vulnerability sits in how WebKit hands off WebAuthn requests to the operating system. When a site initiates a passkey flow, the network request can be handled by a system-level credential service instead of going through Safari’s normal browser stack. Because iCloud Private Relay only protects Safari browsing and does not route every application’s traffic through the same protected connection, these OS-level calls bypass the Private Relay path entirely.
That design choice turns into an iCloud Private Relay leak: during the passkey prompt, the destination server receives your true IP address instead of the masked one. A malicious operator does not need malware or phishing tricks; they only need you to visit a page wired around a passkey check, real or fake, and they can log your IP. The interaction looks like a normal passkey dialog to you, which makes this more dangerous than obvious tracking scripts.
Who Is Affected and How Bad Is the Leak?
This is an IP address exposure problem, not a device takeover. The flaw is an information leak that causes loss of anonymity, and it is separate from actively exploited WebKit zero days where crafted web content compromises devices. But that does not make it harmless. An IP address can reveal your network provider, rough location, and can be combined with other data for profiling or targeted attacks.
Any iPhone user who turns on iCloud Private Relay for IP masking in Safari is within scope, because all iOS browsers are forced to use WebKit and inherit the same behavior. The iCloud Private Relay leak also hits privacy-focused tools like OnionBrowser on the Tor network, where researchers observed real IPs leaking through these passkey-linked requests. OnionBrowser’s creator has pointed out that at least two of the leaks are under Apple’s control, underscoring that app developers cannot fully patch around the platform’s limitations.
Why Private Relay Is Not a VPN—and Why That Matters Now
This incident highlights a hard truth: Private Relay is not a system-wide VPN and never was. Private Relay is meant to mask an iCloud+ subscriber’s IP address only while browsing in Safari, and it does not route all application traffic through a single encrypted tunnel. That limited design becomes critical when other parts of the operating system begin making requests, as happens with passkey flows.
Because these passkey-related network calls originate outside the Safari proxy, they slip past Private Relay’s protections and send your real IP downstream. Meanwhile, traditional VPNs that operate at the OS level remain unaffected because they encrypt all outbound traffic rather than relying on browser-based proxies. Users who treated Private Relay as a replacement for a full VPN—especially for anonymous browsing or sensitive research—have been overestimating its privacy guarantees.
What You Should Do Until Apple Ships a Fix
Apple has acknowledged the report and says it is investigating; there is no published timeline or technical details for a fix yet. Hoping that a future update quietly makes this go away is not a strategy. You should assume that passkey prompts on iOS can expose your real IP address whenever they are used, even with Private Relay turned on.
Until Apple patches WebKit’s behavior, be cautious with unfamiliar sites that request or imitate passkey support, especially when anonymity matters. Apply iOS and browser updates as soon as they are released, and if you need Tor-level anonymity, use the official Tor Browser on supported platforms rather than relying on OnionBrowser or Private Relay alone. For high-privacy needs on iPhone, treat Private Relay as a mild privacy enhancement, not a shield—pair it with a system-wide VPN and assume that any passkey authentication vulnerability can be abused to unmask your IP.



