Private Relay is supposed to do one thing: keep the sites you visit in Safari from seeing where you actually are. Researchers say it doesn’t reliably do that thing.
Talal Haj Bakry and Tommy Mysk published a blog post Tuesday laying out a set of flaws that let a website pull a Private Relay user’s real IP address anyway. They also built a site where you can check yourself. We ran the check Tuesday. It returned our real IP address.
404 Media reported the issue first.
The flaws sit in WebKit, not in Private Relay’s plumbing
Bakry and Mysk wrote that the problem traces to three features in WebKit, Apple‘s browser engine. That detail matters more than it sounds. Every browser on iOS runs on WebKit, whatever name is on the icon.
What Private Relay was never going to do for you
People buy iCloud+ and assume they’ve bought a VPN. They haven’t. A VPN covers your IP address at the system level, across every app on the device. Private Relay is opt-in, it’s limited to iCloud+ subscribers and it only does anything at all while you’re in Safari.
So the coverage was always narrow. The finding here is that even inside that narrow window, the protection can be worked around.
They didn’t tell Apple, and they said why
Most researchers file with the vendor and sit on the details. Mysk skipped that step and posted the reasoning on X: “our past experience with Apple tells us that reporting this issue would involve months of delays, inconsistent communication, and in some cases, denying the issue’s impact entirely.”
Read that as a disclosure decision you’re allowed to disagree with. It also means there’s no patch timeline to point at.
Apple did not immediately respond to a request for comment.
Worth knowing who’s telling you this
Mysk and his colleagues make a private browser called Psylo, and they say Psylo now has mitigations that stop users’ IP addresses from leaking. The people who found the leak also sell the thing that plugs it. That doesn’t make the finding wrong, and our own test lines up with it. It’s context you should carry into the reading.
If your threat model depends on your IP address staying hidden, go run the researchers’ check on your own device and see what comes back. Then decide whether the Safari-only, iCloud+-only toggle you’ve been trusting was ever the right tool for it.