
Apple Private Relay is meant to make web browsing more private, but new research shows why users should not treat it like a full VPN or an absolute shield.
Security researchers Talal Haj Bakry and Tommy Mysk disclosed that Apple iCloud Private Relay can be bypassed in some cases, allowing websites to learn a user real IP address even when the feature is enabled. Mallory tracked the disclosure, noting that the issue involves WebKit behaviours including WebAuthn flows tied to passkeys, DNS prefetching in iOS 26 and WebTransport in iOS 26.4.
TechCrunch said it verified that a test site could reveal a real IP address, while the issue was first reported by 404 Media. Apple reportedly said it is investigating the report.
Private Relay is an iCloud+ feature that routes Safari traffic through separate relays so websites do not directly see a user exact IP address and Apple does not see the website being visited. It is useful, but it is not the same as a system-wide VPN. It mainly protects Safari traffic, and like any privacy feature, its effectiveness depends on how browsers, protocols and websites behave in practice.
That distinction matters because many users read privacy marketing as a promise of total invisibility. Real privacy tools rarely work that way. They reduce exposure, but they can still have edge cases, protocol leaks, app limitations or design assumptions that break under unusual conditions.
The reported Private Relay issue is especially sensitive because it sits inside WebKit, the browser engine Apple requires third-party browsers to use on iOS. That means the exposure may not be limited to Safari alone. Some third-party browsers on iPhones could also be affected if they rely on the same underlying behaviour.
For ordinary users, the practical response is simple. Keep software updated, avoid assuming that Private Relay hides everything, and use a trusted VPN if the goal is broader network-level privacy across apps. Users handling sensitive work should also avoid testing anonymity with only one tool, especially on websites that can trigger browser features like passkeys, prefetching or new transport protocols.
This fits a wider pattern around consumer privacy features. Apple generally has a stronger privacy reputation than most large tech companies, but reputation does not remove the need for technical scrutiny. Privacy products must be tested like security products because small leaks can defeat the user expectation behind the feature.
The story also connects with recent data and cyber-risk coverage. We have written about customer data exposure creating phishing risk and ad-tech data being weaponised for cyberattacks. The common lesson is that metadata matters. IP addresses, location hints, email addresses and phone numbers may look limited, but they can be combined to identify, track or target people.
Apple will likely patch or mitigate the issue if the investigation confirms the reported behaviour. But the broader lesson will remain. Privacy tools are not magic switches. They are technical systems, and technical systems need constant testing because the web keeps changing underneath them.







