Skip to content
Apple's Private Relay Vulnerability Exposes Users' IP Addresses

Apple's Private Relay Vulnerability Exposes Users' IP Addresses

First seen 5 Aug 2026, 19:31 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 6, 2026 at 16:10 UTC
  • Apple's Private Relay can leak real IP addresses due to flaws in passkey processing.
  • Researchers created a site to test for IP leaks, confirming the vulnerability.
  • Apple has acknowledged the issue but has not committed to a timeline for resolution.

Security researchers have discovered that Apple's iCloud Private Relay can inadvertently expose users' real IP addresses due to flaws in how passkeys are processed. This issue arises when requests bypass Safari's proxy protections, allowing websites to see the user's actual IP address. The researchers, Tommy Mysk and Talal Haj Bakry, created a testing site demonstrating the leak. They opted not to report the issue to Apple due to past experiences with delayed responses. The vulnerability affects users of Private Relay and the OnionBrowser app, but not the official Tor Browser. Apple acknowledged the severity of the issue but has not provided a timeline for a fix. The researchers have developed a private browser called Psylo, which mitigates the IP leak problem.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 46d ago How this analysis works

Timeline

2026-08-05
Research on Private Relay vulnerability published
Security researchers revealed that Apple's Private Relay can expose users' real IP addresses due to flaws in passkey handling.
Rss.Slashdot
2026-08-05
Testing site for IP leaks launched
Researchers launched a website allowing users to check if their real IP address is exposed while using Private Relay.
Techcrunch
2026-08-05
Apple informed about the vulnerability
Researchers communicated the issue to Apple, which acknowledged its severity but did not provide a fix timeline.
Rss.Slashdot

More articles in this cluster (6)