A critical vulnerability in Apple's widely-promoted privacy protection service threatens to expose user IP addresses to the internet, according to findings published by cybersecurity researchers Talal Haj Bakry and Tommy Mysk. The researchers discovered that Apple's Private Relay, a premium feature included with iCloud+ subscriptions, inadvertently leaks internet protocol addresses through three separate flaws in WebKit, the browser engine that Apple mandates all iOS browsers must use. The discovery raises significant questions about the effectiveness of Apple's privacy protections at a time when the company has heavily marketed its commitment to user security.

The vulnerability affects not only Apple's Safari browser but potentially every iOS browser available on the App Store, since Apple's strict policies require them all to rely on the same WebKit engine. This includes Tor browsers and other privacy-focused applications like Psylo, a private browser developed by the researchers themselves. When Psylo users reported experiencing DNS leaks on certain websites, Bakry and Mysk investigated and traced the issue to fundamental weaknesses in how WebKit handles certain network requests. The findings demonstrate how a single mandatory system component can create widespread security vulnerabilities across an entire platform's ecosystem.

The flaw became apparent through an ironic situation: while Private Relay employs a sophisticated two-relay system designed to prevent any single entity—including Apple itself—from viewing both a user's identity and their browsing activity simultaneously, the feature falters when users employ passkeys. Passkeys represent Apple's modern authentication method, marketed as more secure than traditional passwords. However, the authentication process requires devices to send requests outside the normal browser pathway, completely bypassing Private Relay's protections. This architectural inconsistency means that users implementing one security measure inadvertently undermines another, leaving them exposed to location tracking and identity correlation.

The significance of IP address exposure extends beyond simple location identification. Internet protocol addresses function as digital fingerprints for internet-connected devices, revealing a user's approximate geographic location down to postal code level. Internet service providers, website operators, and other third parties routinely monitor and log this information to track user behaviour across the web. This tracking infrastructure enables everything from targeted advertising to activity profiling. Malicious actors can exploit exposed IP addresses to launch specific cyberattacks, identify device vulnerabilities, or conduct reconnaissance before launching more sophisticated intrusions. For Malaysian users concerned about digital privacy or those operating in restrictive environments, IP address concealment represents a critical security consideration.

Apple's emphasis on privacy as a core brand differentiator makes this discovery particularly problematic. The company launched an advertising campaign in June highlighting Safari's supposed superiority over competitors like Google Chrome in protecting user privacy. This marketing narrative depends on consumer confidence in Apple's privacy infrastructure. The company introduced Intelligent Tracking Prevention back in 2017, followed by Private Relay in 2021, each presented as advancing user protection. The gap between Apple's privacy promises and the technical reality of these vulnerabilities suggests either inadequate security testing or insufficient understanding of how various features interact within the broader system.

The distinction between Private Relay and Safari's Private Browsing feature, while important technically, may confuse average users trying to protect their privacy. Safari's Private Browsing prevents local storage of browsing history within specific tabs but provides no network-level protection against tracking. Private Relay, by contrast, operates at the network level and requires an iCloud+ subscription, positioning it as a premium service for serious privacy-conscious users. The vulnerability undercuts the value proposition of this paid service, raising questions about whether consumers are receiving the protection they expect when paying for enhanced privacy.

The researchers have already taken steps to address the problem in their own Psylo browser and notified other affected parties including the Tor Project and Onion Browser developers. Their proactive disclosure demonstrates responsible cybersecurity research practices and provides a template for how developers should respond when discovering systemic vulnerabilities. However, the fact that independent researchers discovered these flaws rather than Apple's internal security teams raises concerns about the company's security testing procedures and whether privacy features receive appropriate engineering scrutiny before public release.

For Southeast Asian users, the implications are particularly acute. In jurisdictions where government surveillance or corporate tracking presents genuine risks, privacy tools like Private Relay carry real significance. Users in Malaysia and neighbouring countries may have relied on these features precisely because Apple branded them as protective measures. The discovery that these protections contain fundamental flaws without users' knowledge represents a breach of the implicit trust placed in Apple's privacy commitments. Additionally, users whose browsing patterns, locations, or online activities might attract unwanted attention from authorities or malicious actors face heightened risk from these IP address leaks.

The technical root cause—flaws in the mandatory WebKit engine—suggests Apple may need to fundamentally reconsider its platform architecture. Requiring all browsers to use a single rendering engine provides Apple with consistency and security review opportunities, but creates a single point of failure. When WebKit contains vulnerabilities affecting privacy, no alternative implementation exists for iOS users seeking better protection. This monoculture approach, while defensible from Apple's control perspective, undermines the diversity-based security that would emerge if developers could choose alternative browser engines.

Apple's silence on the matter, having not responded to requests for comment from multiple publications, leaves questions unanswered about whether the company acknowledges the vulnerability, plans fixes, or considers the exposure levels acceptable. Typically, security researchers expect companies to provide timelines for patches and explanations of their remediation approach. Apple's non-response suggests either an ongoing internal assessment or reluctance to engage with findings that contradict the company's privacy marketing narrative. This approach contrasts with the transparency many users expect from a company building its brand on privacy commitments.

The discovery also highlights how modern device ecosystems involve layered features that may interact in unexpected ways. Private Relay wasn't designed with passkeys in mind—passkeys emerged as a newer security standard that Apple later integrated. This sequential feature development created gaps in the privacy protection model. As authentication methods, privacy tools, and browser functionality continue evolving, ensuring they work cohesively requires ongoing security review rather than one-time assessment during initial feature launches.

Looking forward, this vulnerability exposes a broader question about whether consumers can realistically evaluate privacy claims made by technology companies. Users cannot audit Apple's browser engine code or network infrastructure directly. They must rely on security researchers, journalists, and periodic official audits to validate corporate privacy promises. When mainstream companies like Apple fail to live up to stated privacy protections, it undermines consumer confidence in privacy tools generally and raises the question of what independent verification mechanisms should apply to privacy-critical features. For Malaysia's growing number of digitally-aware users concerned about online privacy, the discovery serves as a sobering reminder that marketing claims require independent validation.