A significant security vulnerability threatens the effectiveness of Apple's Private Relay, the company's premium privacy service bundled with iCloud+ subscriptions. Cybersecurity researchers Talal Haj Bakry and Tommy Mysk revealed in August that three flaws embedded within WebKit—the browser engine that Apple mandates all iOS applications use—can circumvent Private Relay's protections and leak users' actual Internet Protocol addresses to the wider web.
The implications of this discovery extend beyond Apple's own ecosystem. Because App Store regulations require every third-party iOS browser to utilise WebKit, the vulnerability affects not only Safari but also privacy-focused alternatives including Tor Browser and Psylo, a private browser developed by the researchers themselves. The flaw represents a systemic weakness that Apple's strict control over iOS browser technology has inadvertently propagated across the entire platform. Users who selected these applications specifically for enhanced privacy protections may find their faith misplaced.
The researchers uncovered the problem after investigating DNS leak reports from Psylo users experiencing address exposure on certain websites. Their investigation revealed not one but three distinct attack vectors that could reveal a device's genuine IP address. The discovery gained wider attention when technology publication 404 Media reported on the original blog post published in early August, bringing the issue into public discourse and raising questions about Apple's quality assurance processes.
The paradox at the heart of this vulnerability illustrates how modern security features can sometimes create unexpected vulnerabilities. Private Relay, introduced in 2021, employs a dual-relay architecture specifically designed to prevent any single entity—including Apple itself—from simultaneously identifying a user and monitoring their browsing activity. The system represents a meaningful advancement in privacy protection, yet the researchers identified a flaw when users employ passkeys, which represent a newer, more secure alternative to traditional passwords.
Passkeys function differently from conventional authentication mechanisms. When a user employs a passkey to access a service, their device must transmit authentication requests outside the normal browser process, bypassing Private Relay's protective routing entirely. This architectural incompatibility means that while a user believes their connection enjoys the full protection of Private Relay, passkey-based authentication actually leaks their genuine IP address directly to servers, undermining the entire purpose of the subscription service. For Malaysian users who subscribe to iCloud+ specifically for privacy protection, this revelation represents a significant breach of the implicit trust they placed in Apple's premium offering.
Internet Protocol addresses function as unique digital identifiers for all internet-connected devices. These numerical addresses enable data routing and network communication but simultaneously reveal sensitive information about device owners. IP addresses can pinpoint a user's approximate geographic location down to the postal code level, enabling internet service providers, website operators, and other interested parties to track browsing patterns and online behaviour. Malicious actors exploit IP addresses to orchestrate specific cyberattacks, according to cybersecurity firm Fortinet, making address concealment a legitimate security concern rather than mere preference.
Apple has consistently marketed its products and services with privacy as a cornerstone value proposition. The company invested considerable marketing resources in a June campaign asserting Safari's privacy superiority over competitors including Google Chrome. Dating back to 2017, Apple introduced Intelligent Tracking Prevention technology incorporating IP address masking capabilities. Private Relay represented the logical evolution of this privacy-focused philosophy, offering subscribers enhanced protection beyond Safari's standard features. This vulnerability therefore strikes at the core of Apple's carefully cultivated privacy reputation.
For regional technology consumers in Southeast Asia, the implications warrant careful consideration. Many Malaysian and regional users have adopted Apple products based on privacy assurances, with some specifically subscribing to iCloud+ for Private Relay protection. The discovery that this premium feature contains exploitable weaknesses raises broader questions about whether proprietary technology companies can genuinely prioritise user privacy when their business models often involve data collection and analysis. The fact that the vulnerability persists in a feature specifically designed to prevent precisely this type of exposure suggests insufficient security testing before commercial deployment.
The researchers have already moved to mitigate the immediate threat. They updated Psylo to protect against the identified flaws and notified relevant stakeholders including the Tor Project and Onion Browser developers, enabling these privacy-focused projects to implement protective measures. However, the core vulnerability residing in WebKit itself requires Apple's intervention, as the company controls the underlying browser engine that all iOS applications must utilise. This centralised architecture, while providing Apple with quality control capabilities, creates single points of failure affecting the entire ecosystem.
Apple's silence on the matter has proven notably conspicuous. The company declined to provide commentary when contacted by technology publication Inc., offering no timeline for fixes, no acknowledgment of severity, and no public roadmap for remediation. This non-response stands in sharp contrast to the company's frequent public statements about privacy commitment, creating a disconnect between corporate messaging and apparent action. Users and security professionals alike await clarity on whether Apple considers this a critical priority worthy of emergency patching or a lower-risk issue suitable for standard release schedules.
The incident underscores a persistent tension within technology security: the difficulty of implementing privacy protections across complex, interconnected systems where different security features interact in unexpected ways. As passkeys continue gaining adoption as a superior authentication mechanism, ensuring their compatibility with privacy infrastructure becomes increasingly important. For Apple, addressing this vulnerability represents not merely a technical correction but an opportunity to reaffirm its stated commitment to user privacy through swift, transparent action.
Malaysian consumers considering Apple's premium privacy services should remain aware that advertised protections may not function as intended in all circumstances. Security researchers recommend scepticism toward any single company's privacy claims, particularly when those companies have financial incentives beyond pure user protection. Until Apple releases detailed information about fixes and implementation timelines, users relying on Private Relay for sensitive browsing activities may prudently consider supplementary privacy tools or temporarily suspending reliance on this feature for high-stakes transactions.
