Apple's Privacy Feature for iPhone Can Accidentally Show Your Real IP Address

Security researchers Talal Haj Bakry and Tommy Mysk announced on August 4, 2026 that Apple's iCloud Private Relay can be tricked into revealing a user's real IP address through problems in Apple's web browser engine (mysk.blog). The researchers set up a website, leaks.psylo.app, where anyone can check whether their IP address leaks while Private Relay is turned on. TechCrunch confirmed the leak on August 5, 2026 (TechCrunch.
Private Relay is a feature for iCloud+ subscribers that makes web browsing more private. It sends your Safari internet traffic through two middlemen, so that neither one can see both who you are and what websites you are visiting. Apple describes it as a service that lets users "connect to and browse the web more privately and securely" (developer.apple.com). On iPad, Apple states it "hides a user's IP address and web browsing activity from network providers and websites" (Apple Support).
An important thing to understand is that Private Relay is not a VPN. A VPN protects all the internet traffic on your device. Private Relay only protects traffic inside Safari, not from other apps or browsers (TechCrunch).
But the new problem is different. The leak comes not from traffic outside Safari but from three specific features inside WebKit, the software engine that powers Apple's browser. Because Apple requires every browser on the iPhone to use WebKit, the flaws affect all iOS browsers, not just Safari. The researchers did not name the three features but said a specially crafted web page can trigger the browser to make network requests that skip past Private Relay's protection (mysk.blog; 404 Media.
Mysk said the researchers chose not to report the issue through Apple's usual security reporting channel. Past experience, he said, involved months of delays, inconsistent communication, and at times denial that a problem was serious (TechCrunch). Instead, they published their findings publicly and built fixes into their own privacy-focused browser, Psylo, which they say prevents the leaks. Those fixes shipped in Psylo version 1.3.1 (mysk.blog.
This is not the first time Private Relay's protection has been challenged. Researchers previously found a vulnerability in Private Relay for iOS 15 that could let third parties get a user's IP address (Bitdefender). Apple's own documentation has acknowledged some edge cases: the security notes for iPadOS 17.7.3 state that adding a website to the Safari Reading List may reveal your IP address to that website (Apple Support). Apple also notes that some websites that use IP filtering or monitoring may need to see your IP even with Private Relay turned on (Apple Support).
Apple did not immediately respond to a request for comment from TechCrunch about the new findings (TechCrunch.
The difference between what Private Relay is designed to do and what it actually covers matters for anyone who has assumed it works like a full VPN. It does not, and Apple's marketing materials stop short of saying it does. But the gap between what users expect from the iCloud+ privacy features and what Private Relay actually delivers has caused confusion since the feature launched. A privacy tool that can be defeated by a crafted web page, using the very browser engine it is meant to protect, is a real limitation.
In my view, Mysk's decision to publish without going through Apple's disclosure process is a calculated trade-off. The usual practice of reporting security flaws privately gives companies time to fix the problem before details become public. But when a researcher has run into delays and pushback from that process before, going public becomes a way to apply pressure. The downside is that the disclosure site itself works as a how-to guide that bad actors can study. For users who need to keep their IP address private, the short-term fix is narrow: use a full VPN, and understand that Private Relay's protection is more limited than the iCloud+ branding suggests.
The deeper structural issue is that every browser on the iPhone must use Apple's WebKit engine. Because of that rule, a flaw in WebKit affecting Private Relay leaves users with no alternative. You cannot switch to a different browser with a different underlying engine to avoid the problem. Apple's policy, which requires all iOS browsers to use WebKit, concentrates the risk: one engine's bug becomes every browser's bug. That is a design choice with security consequences that go well beyond this one finding.


