iCloud Private Relay was designed to be a privacy shield. Apple promised that “no single party — not even Apple — can see both who you are and what sites you’re visiting.” That’s the pitch behind the dual-relay system baked into every iCloud+ subscription. But according to 404 Media, researchers have found a WebKit-based flaw that quietly exposes your real IP address to any website that supports — or even pretends to support — passkeys. Apple says it’s investigating. No fix has shipped.
How the Leak Actually Works
A passkey request sidesteps Safari’s proxy path entirely, exposing the one thing Private Relay was built to hide.
The problem sits in how your device handles passkeys, the WebAuthn-based login credentials Apple has been pushing as the future of passwords. When a site triggers a passkey request, the device’s credential service — not Safari — makes a direct network call that bypasses the relay path completely. Your real IP rides along unprotected. “Any website that supports, or pretends to support, passkeys can see the user’s real IP address despite having iCloud Private Relay on,” according to 404 Media, which confirmed the leak using a researcher-built test site that returned real IP addresses even with Private Relay active.
A few facts worth knowing:
- Private Relay only covers Safari traffic. Apple has never claimed full-device protection.
- The passkey request travels outside the relay, exposing your real IP to the destination server.
- OnionBrowser on iOS is also affected, because Apple mandates WebKit for all iOS browsers.
- The Tor Project’s official Tor Browser is reportedly not affected in the same way.
What This Actually Means for You
The blast radius extends beyond Safari to every iOS browser, thanks to Apple’s mandatory WebKit requirement.
Because every iOS browser runs on WebKit — no exceptions — this flaw isn’t contained to Safari. Think of it like a home security system that only monitors the living room while leaving every other entry point completely unwatched. Private Relay was never a VPN. Apple’s own documentation limits its scope to Safari web browsing, and that gap between perceived and actual protection is exactly where the exposure lives.
For now, a full-device VPN remains the only tool that actually covers all your network traffic.
Apple says it’s looking into the issue, though no public timeline exists for a patch. This marks the second recent Apple privacy stumble, following reports that Hide My Email could secretly tracking users expose real addresses before a quiet fix arrived. Treat Private Relay as a partial privacy layer, not full armor. If real anonymity matters to you, a VPN is still the more complete answer.





























