One Apple iCloud feature, designed to offer secure browsing, can leak your IP address, potentially revealing your identity or location. Security researchers from the software company Mysk have found that iCloud Private Relay is not as private as Apple says.
Private Relay isn't doing its job very well, for a paid subscription feature. | Image by CNET
This iCloud+ feature is a privacy service that hides your IP address and encrypts your Safari browsing traffic.
iCloud Private Relay routes your web requests through two separate internet relays — one operated by Apple and one by a third party — so no single entity can see both who you are and what site you visit
- Apple support page
As it turns out, Private Relay isn't doing its job very well. Two researchers from a small independent company have found a simple way to circumvent Private Relay and display the IP address of a device or a home network.
Mysk is a team of two from Canada and Germany. We build privacy-respecting apps for Apple platforms and publish research on cybersecurity and privacy topics
- Mysk official site
Have you checked if you're affected by the Private Relay vulnerability?
Your IP is out in the open
Check out if you're affected with the tool that Mysk has set up. | Image by PhoneArena/Mysk
404 Media reports that Talal Hak Bakry and Tommy Mysk, the two researchers from Mysk, found the problem in something called passkeys. It's a more user-friendly and easy way to sign into sites instead of using a username and a password.
Recommended For You
Apparently, using this method circumvents Private Relay and the IP is visible to the destination server or site.
Because the fetch is issued by the operating system’s credential service rather than by Safari, it never enters Private Relay’s proxied path. The destination server sees the device’s real IP address either way.
- Talal Hak Bakry and Tommy Mysk, Mysk official blog
The IP address is a unique number that allows servers and other computers to identify your device and connect to it. It's your internet post code, so to speak and is tied to the physical location of your network.
If your IP is not private, you basically broadcast your location to everybody. Malicious parties can use the IP to reveal private information about you, impersonate you, or, in the least problematic scenario, target you with ads and spam.
Myst didn't reach out to Apple and made the vulnerability public straight away
In a post on X, Talal Hak Bakry and Tommy Mysk shared that they decided to go public with the issue, rather than contacting Apple first. According to the researchers and their past experience with Apple, reporting the issue would've resulted in months of delays and Apple possibly even denying the issue.
In an ideal world, we’d report the issues to Apple, they acknowledge the issue, and ship a fix in a timely manner. Unfortunately, our past experience with Apple tells us that reporting this issue would involve months of delays, inconsistent communication, and in some cases, denying the issue’s impact entirely
- Mysk official account on X
No official comment from Apple at the time of this writing.
How to check if you're affected and your IP is visible?
The researches have set up a website that lets people check whether they're affected by the vulnerability and their IP is visible.
You can find your IP under WebAuthn. | Images by Image by Mysk
We tested the vulnerability with my colleague Iskra on her MacBook Air M3 (running macOS Sequoia 15.6) and iPhone 13 Pro Max (running iOS 26.5). You can see the results above. The MacBook successfully hid her IP, but the iPhone 13 Pro Max displayed it in full (removed in the screenshot).
What to do next?
ProtonVNP is a Swiss service that's fast, secure and has a free tier. | Image by Proton
There are a couple of things you can do if you've been affected by this vulnerability. I won't tell you to stop using your Apple devices and switch to Android, that's too radical.
You can, however, install a third-party VPN (such as ProtonVPN) that will hide your IP and create a secure browsing tunnel for you on the internet (we're not affiliate with Proton and this is our own recommendation). The two security researchers who found the vulnerability also recommend using a VPN until Apple patches the issue.
It’s also worth noting that these leaks do not affect VPNs. Users who are concerned can reduce their exposure today by using a VPN while waiting for platform-level fixes.
- Myst official X account
In our case, changing the browser didn't help, so Safari, Chrome, or Mozilla all displayed the IP on the test site. There are, however security-centric browsers that may help, such as Onion Browser, and TOR browser. We'll continue to monitor the situation and inform you on any development.
Read more news about breaches and vulnerabilities here:
Mint Mobile is now allowing you to get whichever plan you like for either three, six, or 12 months for just $15/mo. If you go for the six-month unlimited service, for instance, you'll now have to pay just $90 upfront instead of $210.
Mariyan, a tech enthusiast with a background in Nuclear Physics and Journalism, brings a unique perspective to PhoneArena. His childhood curiosity for gadgets evolved into a professional passion for technology, leading him to the role of Editor-in-Chief at PCWorld Bulgaria before joining PhoneArena. Mariyan's interests range from mainstream Android and iPhone debates to fringe technologies like graphene batteries and nanotechnology. Off-duty, he enjoys playing his electric guitar, practicing Japanese, and revisiting his love for video games and Haruki Murakami's works.
A discussion is a place, where people can voice their opinion, no matter if it
is positive, neutral or negative. However, when posting, one must stay true to the topic, and not just share some
random thoughts, which are not directly related to the matter.
Things that are NOT allowed:
Off-topic talk - you must stick to the subject of discussion
Offensive, hate speech - if you want to say something, say it politely
Spam/Advertisements - these posts are deleted
Multiple accounts - one person can have only one account
Impersonations and offensive nicknames - these accounts get banned
To help keep our community safe and free from spam, we apply temporary limits to newly created accounts:
New accounts created within the last 24 hours may experience restrictions on how frequently they can
post or comment.
These limits are in place as a precaution and will automatically lift.
Moderation is done by humans. We try to be as objective as possible and moderate with zero bias. If you think a
post should be moderated - please, report it.
Have a question about the rules or why you have been moderated/limited/banned? Please,
contact us.
Things that are NOT allowed:
To help keep our community safe and free from spam, we apply temporary limits to newly created accounts: