Home / Apple

Photo of software, code, tablet
Image: Wikipedia
Apple

Apple's Private Relay Security Flaw Can Leak IP Addresses via Passkeys

WireByte Staff · August 6, 2026

Security researchers Talal Haj Bakry and Tommy Mysk discovered a vulnerability in Apple's WebKit browser engine affecting the iCloud+ Private Relay feature. The flaw can expose users' IP addresses to websites when logging in with passkeys. The issue impacts Safari and other iOS browsers like OnionBrowser, prompting an ongoing investigation by Apple.

Key points

  • Security researchers Talal Haj Bakry and Tommy Mysk identified a vulnerability in Apple's WebKit engine that compromises the iCloud+ Private Relay feature.
  • The flaw allows user IP addresses to leak to websites and online services when authenticating via passkeys through the Safari browser.
  • The issue affects not only Safari on iOS but also alternative privacy-focused browsers utilizing WebKit, such as OnionBrowser and Psylo.
  • The researchers reported that passkey authentication requests bypass standard browser shielding because they occur outside the browser interface.
  • Apple informed media outlets that the company is currently investigating the reported vulnerability.

A newly discovered vulnerability in Apple's WebKit browser engine can expose users' Internet Protocol addresses despite the active use of the iCloud+ Private Relay feature. Security researchers Talal Haj Bakry and Tommy Mysk revealed that the intended anonymity tool fails to mask user IP addresses during specific login procedures on Apple's Safari browser.

The security flaw is tied to the implementation of passkeys, an increasingly popular password-free authentication method. According to the findings, when a user initiates a passkey login, the device executes the authentication request outside of the standard browser environment. Because Private Relay is strictly bound to Safari rather than operating as a full-device virtual private network, the process can inadvertently reveal the user's actual network location to destination websites and services.

The issue extends beyond Apple's native browser. Since all iOS browsers are required to utilize the WebKit engine, privacy-oriented alternatives such as OnionBrowser and the researchers' Psylo browser are similarly vulnerable to the IP leakage when handling passkeys. The researchers stated they have already reached out to the Tor Project and OnionBrowser developers to communicate their findings and discuss potential technical solutions.

In response to the disclosure, Apple confirmed to reporters that the company is actively investigating the WebKit issue. The findings highlight the architectural limitations of browser-specific privacy tools compared to comprehensive system-wide encryption services.

Sources

WireByte Staff — Editorial Team

The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.