Researchers Find Three Ways Apple Traffic Can Bypass iCloud Private Relay

Researchers found three Apple request paths that may bypass iCloud Private Relay, potentially exposing users’ IP addresses or DNS activity.

Aug 6, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Security researchers Talal Haj Bakry and Tommy Mysk have identified three request paths involving Apple’s browser and authentication technologies that can bypass proxy protections and expose a user’s real network information.

The flaws affect Apple’s iCloud Private Relay, a paid iCloud+ feature designed to hide users’ IP addresses and DNS information while browsing in Safari. They also affect some WebKit-based browsers that rely on Apple’s proxy configuration system, including privacy-focused browsers on iOS.

According to the researchers, the problem comes from three WebKit features: DNS prefetching, WebAuthn Related Origin Requests and WebTransport.

The three features “bypass the configured proxy and send traffic directly from the device, which exposes the user’s real network,” the researchers wrote in their report.

The researchers said they verified the issue through a proof-of-concept website that can show whether a user’s real IP address is exposed while Private Relay is enabled.

WebAuthn requests create the biggest privacy risk

The most concerning issue involves WebAuthn, the technology behind passkeys. The issue does not compromise passkey cryptography itself.

Passkeys normally improve security by replacing passwords with cryptographic credentials stored on a device. However, researchers found that some WebAuthn requests are handled outside Safari by Apple’s operating system credential service. That means those requests do not travel through Private Relay’s protected route.

“Because the fetch is issued by the operating system’s credential service rather than by Safari, it never enters Private Relay’s proxied path. The destination server sees the device’s real IP address either way,” the researchers wrote.

A website does not necessarily need a user to log in or interact with a passkey prompt to trigger the request, according to the findings. A site designed to exploit the behavior could potentially collect the real IP address of a Private Relay user.

Advertisement

Other WebKit features also bypass protection

The researchers identified two additional paths that can leak information. DNS prefetching, a browser performance feature that speeds up page loading by resolving domains early, can send DNS requests through the device’s normal connection instead of Private Relay, potentially exposing DNS activity and related network information.

WebTransport, a newer communication technology built on HTTP/3, can create direct connections that bypass the configured proxy and expose the device’s IP address. The issues may extend beyond Safari because most iOS browsers use WebKit, although Apple permits qualifying browsers in the European Union to use alternative engines. That means other browsers using Apple’s engine may also be affected.

A properly configured device-wide VPN should cover these request paths because it protects a broader range of traffic than Private Relay, although coverage depends on the VPN’s routing and DNS settings.

Privacy feature faces fresh scrutiny

The discovery highlights a key difference between Private Relay and a full VPN. Apple designed Private Relay to protect Safari browsing traffic, not every connection made by an iPhone or Mac.

Apple describes Private Relay as a system that prevents network providers and websites from easily linking a user’s identity with their browsing activity. But these findings show that browser features operating outside the normal web traffic path can weaken those protections.

The issue also comes shortly after another privacy concern involving Apple’s Hide My Email feature, which researchers said exposed some users’ real email addresses under certain conditions.

For users who rely on Private Relay for stronger anonymity, the main takeaway is that browser-level privacy tools can have limits. Features designed to improve convenience or performance may create unexpected paths around those protections if they are not integrated into the same security model.

Advertisement

Apple told 404 Media that it is investigating the researchers’ report but has not announced a fix timeline. 

Also read: Apple recently patched an actively exploited zero-day flaw affecting multiple operating systems.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.