READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Apple's Private Relay, Sold as an IP Address Shield, Can Be Bypassed to Expose Your Real Location

Apple's Private Relay, Sold as an IP Address Shield, Can Be Bypassed to Expose Your Real Location
Security researchers found that Apple's Private Relay, a paid privacy feature for iCloud+ subscribers, can be tricked into revealing a user's actual IP address through flaws in three WebKit features. The researchers built a public test site that confirms the leak, and TechCrunch verified it works. Apple has not fixed it or publicly responded as of this reporting.

Apple charges iCloud+ subscribers for a feature called Private Relay that's supposed to hide your real IP address when you browse with Safari. Turns out it doesn't always work.

Security researchers Talal Haj Bakry and Tommy Mysk published findings this week showing that Private Relay can be circumvented, exposing the exact IP address it's designed to conceal. TechCrunch independently tested the researchers' public leak-check website and confirmed it revealed the outlet's real IP address despite Private Relay being active.

What's actually broken

According to the researchers' blog post, the problem isn't with Private Relay itself in some abstract sense. It's with three specific features baked into WebKit, the browser engine that powers Safari and, by Apple's own App Store rules, every browser on iOS. Because WebKit sits underneath the hood of any iOS browser, the flaw isn't limited to people who think of themselves as "Safari users."

That distinction matters. Private Relay was never marketed as a full VPN. It only works inside Safari, and it operates at the browser level, not the system level, unlike a real VPN that reroutes all device traffic. Apple's own positioning has always been narrower than a VPN's. But narrower doesn't mean it should leak the one thing it explicitly promises to hide.

Why the researchers skipped Apple

Mysk didn't report the bug to Apple before going public. On X, he explained the decision bluntly: past experience taught him that flagging issues to Apple "would involve months of delays, inconsistent communication, and in some cases, denying the issue's impact entirely."

That's a serious allegation about Apple's vulnerability-response process, and it's important to be precise about what it is and isn't. It's Mysk's characterization of his own past dealings with the company, not a documented pattern verified by an outside audit. Apple did not respond to TechCrunch's request for comment on the Private Relay findings, and there's no independent record cited in the reporting confirming or refuting Mysk's account of prior slow-walking. Readers should treat it as one security researcher's stated reason for going public, not an established fact about Apple's internal practices.

Still, the decision to skip coordinated disclosure and publish a public leak-testing tool instead is unusual and puts pressure on Apple to respond faster than it might have otherwise.

The researchers have skin in the game

Mysk and his colleagues build a competing private browser called Psylo, which they say already includes mitigations against this exact kind of IP leak. That's not a reason to dismiss the findings. TechCrunch independently verified the leak using the researchers' test site, but it is a relevant financial interest readers should know about when weighing how the story is framed.

What Apple has and hasn't said

As of this reporting, Apple has not issued a public statement, confirmed the flaw, or announced a patch timeline. No CVE, security advisory, or fix has been reported. That silence is itself notable given that Private Relay is a paid feature bundled into iCloud+ plans that Apple markets specifically on privacy grounds.

The bigger picture on "privacy" features

This isn't the first time a marketed privacy tool has fallen short of its promise, and it won't be the last. The lesson isn't that privacy tech is a scam. It's that "opt-in privacy feature from a trillion-dollar company" is not the same as "verified privacy guarantee." Apple's entire brand positioning for the last decade has leaned on privacy as a premium differentiator from Google and Facebook. A leak in a paid privacy feature undercuts that pitch directly.

For consumers, the practical takeaway is straightforward: if you're paying for iCloud+ and relying on Private Relay to actually hide your IP address from websites while browsing, it currently may not be doing that job reliably. People with real safety concerns tied to IP exposure, journalists, domestic abuse survivors, activists, shouldn't treat Private Relay as a substitute for a dedicated VPN until Apple confirms a fix.

The open question is how fast Apple moves. WebKit ships across every iOS browser by Apple's own App Store mandate, so a fix likely requires an iOS-wide update, not a narrow Safari patch. No timeline has been announced. Until one is, anyone can check their own exposure using the researchers' public test tool, and based on TechCrunch's test, plenty of people will find the shield isn't as solid as advertised.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchPSA: Apple’s Private Relay can leak your real IP address