Apple's Private Relay, a privacy feature for iCloud+ subscribers designed to obscure user IP addresses when browsing with Safari, has been found to have vulnerabilities that allow for the circumvention of its protections. Researchers Talal Haj Bakry and Tommy Mysk detailed these flaws, which stem from issues within Apple's WebKit browser engine, used across all iOS browsers. They have also launched a website enabling users to test whether their real IP addresses are being exposed even with Private Relay enabled.
The researchers stated they chose not to report the issue directly to Apple, citing a history of lengthy delays and potential denial of problems in past interactions with the company. Private Relay functions solely within Safari and is distinct from system-level VPNs. Apple did not immediately respond to a request for comment.