One Tap on a Passkey and Your IP Is Exposed: The Hidden Flaw Inside Apple’s Private Relay.

A WebKit flaw in passkey handling lets any website capture real IP addresses across all iOS browsers, with no patch yet

Nikshep Myle Avatar
Nikshep Myle Avatar

By

Image: Apple

Key Takeaways

Key Takeaways

  • A WebKit flaw exposes real IP addresses despite iCloud Private Relay being active.
  • Passkey requests bypass Safari’s relay path, sending real IPs directly to destination servers.
  • All iOS browsers are affected because Apple mandates WebKit; only a full-device VPN protects fully.

iCloud Private Relay was designed to be a privacy shield. Apple promised that “no single party — not even Apple — can see both who you are and what sites you’re visiting.” That’s the pitch behind the dual-relay system baked into every iCloud+ subscription. But according to 404 Media, researchers have found a WebKit-based flaw that quietly exposes your real IP address to any website that supports — or even pretends to support — passkeys. Apple says it’s investigating. No fix has shipped.

How the Leak Actually Works

A passkey request sidesteps Safari’s proxy path entirely, exposing the one thing Private Relay was built to hide.

The problem sits in how your device handles passkeys, the WebAuthn-based login credentials Apple has been pushing as the future of passwords. When a site triggers a passkey request, the device’s credential service — not Safari — makes a direct network call that bypasses the relay path completely. Your real IP rides along unprotected. “Any website that supports, or pretends to support, passkeys can see the user’s real IP address despite having iCloud Private Relay on,” according to 404 Media, which confirmed the leak using a researcher-built test site that returned real IP addresses even with Private Relay active.

A few facts worth knowing:

  • Private Relay only covers Safari traffic. Apple has never claimed full-device protection.
  • The passkey request travels outside the relay, exposing your real IP to the destination server.
  • OnionBrowser on iOS is also affected, because Apple mandates WebKit for all iOS browsers.
  • The Tor Project’s official Tor Browser is reportedly not affected in the same way.

What This Actually Means for You

The blast radius extends beyond Safari to every iOS browser, thanks to Apple’s mandatory WebKit requirement.

Because every iOS browser runs on WebKit — no exceptions — this flaw isn’t contained to Safari. Think of it like a home security system that only monitors the living room while leaving every other entry point completely unwatched. Private Relay was never a VPN. Apple’s own documentation limits its scope to Safari web browsing, and that gap between perceived and actual protection is exactly where the exposure lives.

For now, a full-device VPN remains the only tool that actually covers all your network traffic.

Apple says it’s looking into the issue, though no public timeline exists for a patch. This marks the second recent Apple privacy stumble, following reports that Hide My Email could secretly tracking users expose real addresses before a quiet fix arrived. Treat Private Relay as a partial privacy layer, not full armor. If real anonymity matters to you, a VPN is still the more complete answer.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →