Apple Private Relay Flaws Can Expose Safari Users’ Real IP Addresses
Researchers say flaws in Apple’s WebKit can expose real IP addresses despite iCloud Private Relay, with TechCrunch confirming the leak in a live test.
Summary
Verified facts, On August 5, 2026, TechCrunch reported that Apple’s iCloud Private Relay can be circumvented, potentially exposing the real IP address it is intended to conceal during Safari browsing. Security researchers Talal Haj Bakry and Tommy Mysk disclosed the issue in a blog post published the previous Tuesday. They also launched a website that lets visitors check whether their actual IP address is visible despite having Private Relay enabled. TechCrunch said it used the site on Tuesday and independently observed its real IP address being revealed. The issue was first reported by 404 Media.
Verified facts, Bakry and Mysk attributed the leak to three features in WebKit, Apple’s browser engine. WebKit underpins Safari and, because of Apple’s platform requirements, all web browsers on iOS. The source article does not identify those three features or explain the technical steps used to trigger the disclosure, so their individual roles cannot be assessed from this report alone. The researchers characterized the problem as a series of flaws rather than a single isolated defect.
Background, Private Relay is an optional privacy feature available to paying iCloud+ subscribers. It is designed to obscure a Safari user’s IP address, which can otherwise reveal information about the user’s network and approximate location. However, Private Relay is not a conventional virtual private network: according to the article, its protection is tied to Safari browsing rather than operating across the entire device at the system level. That narrower scope is important because users may incorrectly assume it provides the same coverage as a full-device VPN.
Verified response, Mysk said on X that the researchers did not report the issue directly to Apple. He cited their previous experience with what he described as long delays, inconsistent communication and disputes over the impact of reported problems. That is the researchers’ account and was not independently corroborated in the article. Apple did not immediately respond to TechCrunch’s request for comment. Mysk and his colleagues also develop the private browser Psylo, which they said now includes mitigations intended to prevent this form of IP-address leakage.
Interpretation and next steps, The finding matters most to iCloud+ subscribers who enabled Private Relay because they wanted to limit IP-based tracking or location inference while using Safari. TechCrunch’s successful test provides evidence that the leak was reproducible in at least one environment, but the article does not establish how many users are affected, which iOS or Safari versions are vulnerable, whether exploitation requires user interaction, or whether the test site’s technique works consistently. Apple had not confirmed the issue, announced a fix or provided a timetable when the report was published. Users therefore lacked an official patch status, and the duration and full practical severity of the exposure remained uncertain.
Positives
- Bakry and Mysk created a public website that allows users to test whether Private Relay is exposing their real IP address.
- TechCrunch independently tested the researchers’ website on Tuesday and confirmed that it could reveal the publication’s real IP address.
- Mysk and his colleagues said their Psylo private browser now includes mitigations designed to block the reported IP-address leak.
Risks & concerns
- The researchers said three WebKit features can be used to circumvent Private Relay and reveal an IP address that users expected the service to hide.
- Because WebKit is used by all browsers on iOS, the underlying browser-engine behavior may have implications beyond Safari, although the article only describes Private Relay as working with Safari.
- Apple had not responded to TechCrunch or announced a fix when the August 5, 2026 report was published.
- The researchers chose not to notify Apple directly, citing previous delays and communication problems, which leaves uncertainty about whether Apple had begun investigating the flaws.
- The report does not specify affected software versions, the number of exposed users or the conditions required to reproduce the leak.
