Apple’s Private Relay Isn’t So Private After All, Can Leak Your IP Address

2 hours ago 2

Apple’s iCloud Private Relay feature is designed to obscure your web traffic so sites like advertisers, unscrupulous governments or malicious attackers can’t trace that traffic back to you. But it turns out the mechanism isn’t actually as private as Apple says.

As reported by 404 Media, security researchers at software company Mysk discovered that even with iCloud Private Relay active, the IP address of a device or home network can be transmitted, which could be used to reveal a person’s identity or location.

iCloud Private Relay is a feature for paid customers of Apple’s iCloud Plus service. It routes web traffic through proxy servers, obscuring your IP address and the website address you’re visiting, so neither the site nor Apple can see that information.

It’s also a feature that runs within Apple’s WebKit framework, which includes the Safari browser and other apps and services that use WebKit to access websites. It’s specifically not a VPN (Virtual Private Network), which encrypts all internet traffic and runs it through a proxy server.

The researchers, Talal Hak Bakry and Tommy Mysk, set up a website that lets you check whether your connection is vulnerable. When I tested it using an iPhone 17 Pro and a MacBook Pro with iCloud Private Relay enabled, it correctly identified the IP address of my home internet router.

The information in the red box shows the IP address of my home router.Screenshot by Jeff Carlson/CNET

In a post on X, the researchers noted that they chose to make the vulnerability public rather than report it to Apple first.

“Unfortunately, our past experience with Apple tells us that reporting this issue would involve months of delays, inconsistent communication, and in some cases, denying the issue’s impact entirely,” the researchers wrote. “We weren’t willing to wait months, or upwards of a year, sitting on bugs that undermine the core privacy guarantees of [Mysk’s browser] Psylo and iOS Tor browsers while saying or doing nothing.”

An Apple representative didn’t immediately respond to a request for comment.

How iCloud Private Relay is being bypassed

One problem is related to passkeys, the method of signing into sites that’s more secure and user-friendly than usernames and passwords. WebKit bypasses the Private Relay proxy and sends requested information directly from the device.

“Because the fetch is issued by the operating system’s credential service rather than by Safari, it never enters Private Relay’s proxied path,” the researchers wrote on the Mysk blog. “The destination server sees the device’s real IP address either way.”

There are two other paths that can reveal your IP address even with iCloud Private Relay enabled.

DNS prefetching is a way for websites to request data before it’s needed to speed up the connection. That happens separate from the relay mechanism, so the data is passed directly from your network to the website. However, a site must include the code in its HTML to trigger it.

The third vulnerability is with a low-latency method called WebTransport where WebKit opens a direct connection that bypasses the private relay and sends the user’s real IP address.

Apple’s security also took a hit recently when a bug in Apple’s iCloud Hide My Email feature seemed to expose people’s real email addresses. It, too, is a paid feature of iCloud Plus and is now the focus of a lawsuit accusing Apple of false advertising, fraud and breach of contract.

Jeff Carlson

Jeff Carlson

Senior Writer

Jeff Carlson writes about mobile technology at CNET, from cellular phone plans to devices and emerging technology.

Read Entire Article
Lifestyle | Syari | Usaha | Finance Research