Apple Privacy Tool Springs Leaks

Apple logo on glass storefront
Photo: ZorroGabriel / Shutterstock

Apple’s privacy promise for Safari has hit a hard boundary: researchers say Private Relay can expose a device’s real IP address through WebKit-related features.

Quick Take

  • Researchers say three paths can bypass Private Relay: DNS prefetching, passkey-related WebAuthn requests, and WebTransport.
  • The passkey case matters because the request can come from the operating system’s credential service, not Safari itself.
  • TechCrunch said it verified a live test page that revealed a real IP address with Private Relay turned on.
  • Apple’s own documents show Private Relay is meant to hide Safari traffic, but they also allow websites to request IP visibility.

What the Researchers Reported

Mysk researchers said they found three WebKit features that can step outside the proxy path and reveal user data. Their report points to DNS prefetching, WebAuthn passkey flows, and WebTransport as the main leak paths. In the DNS case, a website can trigger a lookup before the normal relay path starts. In the other two cases, the connection can leave the device directly instead of passing through Private Relay.

TechCrunch said the researchers set up a site where users could check for the leak, and the outlet verified that the page exposed a real IP address during testing. That matters because it moves the story beyond a theory and into a live proof-of-concept. The available material still relies mostly on reporting about the researchers’ work, not the original technical write-up, so the full test method is not in the record here.

Why Passkeys Broke the Privacy Model

The most striking claim is the passkey-related one. According to the reporting, WebKit hands those requests to the operating system’s credential service, not to Safari’s normal browsing path. That means the request can leave outside the Private Relay tunnel. The destination server then sees the device’s real IP address, even though the user believes Safari traffic is protected. That creates a clear gap between the product’s promise and one feature path.

Apple says Private Relay is meant to hide a user’s IP address and browsing activity in Safari through two separate relays. Apple also gives users a way to let a specific website see their IP address for a short time. Those two facts matter because they show both the privacy goal and the built-in exception model. The new reports suggest the leak is not the exception screen working as designed, but a separate route around it.

What This Means for Users and Apple

The wider issue is trust. Privacy tools lose value fast when users think “protected” traffic can still slip out through browser features most people never notice. That risk grows when the problem sits inside a complex stack that blends Safari, WebKit, operating system services, and relay rules. The available reports also say the issue affects other iOS browsers that rely on WebKit, which makes the scope bigger than one app.

At the same time, the evidence points to a conditional leak, not a blanket collapse of all Private Relay traffic. The reports tie the problem to specific actions like opening pages that use prefetching, passkeys, or WebTransport. No Apple advisory or fix note appears in the provided record, so the remediation status is still unclear. For now, the story is less about one broken switch than about how easily privacy claims can fail at the edges.

Sources:

reclaimthenet.org, privacyguides.org, macworld.com, techcrunch.com, discuss.privacyguides.net, timesofindia.indiatimes.com, reddit.com, support.apple.com, developer.apple.com, apple.stackexchange.com, youtube.com, facebook.com, macrumors.com, appleinsider.com, androguider.com, gadgetsnow.indiatimes.com, en.softonic.com, discussions.apple.com