Apple's much-publicized Private Relay privacy feature, marketed as a premium security tool for iCloud+ subscribers, contains a critical vulnerability that undermines its core function of masking user IP addresses from trackers and internet service providers. Security researchers have identified multiple flaws in the underlying technology that allow device IP addresses to be exposed across iOS-based browsers, even when users believe their online activity is fully protected by the service.

The vulnerability traces back to three defective features embedded within WebKit, the browser engine that Apple mandates all iOS browsers must use, including Safari. This requirement means that any browser available on Apple's App Store—from privacy-focused options like Tor browsers to alternatives like Psylo—inherits the same vulnerability through no fault of their individual developers. The flaws were publicly disclosed on August 5 by cybersecurity researchers Talal Haj Bakry and Tommy Mysk, who operate both as independent security researchers and developers of Psylo, a privacy-oriented mobile browser.

The discovery emerged when a Psylo user reported suspicious DNS leaks on specific websites, prompting Bakry and Mysk to investigate further. Their investigation uncovered not just the DNS leak issue but identified two additional pathways through which a device's genuine IP address could be revealed, circumventing Private Relay's protective mechanisms entirely. The implications extend beyond individual apps, as any iOS browser relying on WebKit's API for proxying functionality faces the same exposure, including privacy-centric applications like Tor Browser that users specifically download to shield their identities.

Particularly concerning is the paradoxical nature of how the vulnerability manifests. Private Relay, introduced by Apple in 2021, employs a sophisticated two-relay system designed to prevent any single entity—including Apple itself—from simultaneously viewing both a user's identity and their browsing destinations. However, the flaw emerges precisely when users activate passkeys, a security mechanism that Apple itself has been aggressively promoting as a superior alternative to traditional passwords. When a device needs to authenticate using a passkey, it must make a request outside the browser environment, which forces the connection to bypass Private Relay's protective relay system and directly expose the user's IP address.

This represents a critical design flaw in how Apple's various security features interact with one another. Rather than complementary protections that strengthen overall security, Private Relay and passkeys operate at cross-purposes under certain circumstances. A user who conscientiously subscribes to iCloud+ specifically to access Private Relay, and who follows Apple's recommendations to use passkeys for enhanced account security, ironically becomes more vulnerable to IP address exposure than someone using neither feature. The flaw essentially punishes users for adopting multiple Apple security recommendations simultaneously.

IP addresses function as digital home addresses on the internet, revealing a user's approximate geographical location down to specific postal code levels and enabling tracking of browsing patterns by internet service providers, website administrators, and other entities. This information proves valuable to advertisers seeking to build consumer profiles and concerning to individuals facing surveillance risks or living in jurisdictions with repressive internet policies. Malicious actors also exploit IP address information to orchestrate targeted cyberattacks and network intrusions, according to cybersecurity firms like Fortinet. For Malaysian users particularly, IP address exposure carries additional implications in a region where internet governance and data privacy remain evolving policy areas.

Apple's marketing strategy has consistently positioned the company as a privacy champion, distinguishing its products from competitors like Google's Chrome and Microsoft's Edge. The company spent considerable resources in June launching an advertising campaign that emphasized Safari's superior privacy protections compared with alternatives. This messaging extends back years, with Apple introducing Intelligent Tracking Prevention in 2017 specifically designed to hide user IP addresses from trackers. Private Relay was positioned as the next evolutionary step in this privacy journey, offering users who paid for iCloud+ subscriptions an additional layer of protection that went beyond Safari's standard privacy browsing mode.

The distinction between Private Relay and Safari's Private Browsing feature is important for Malaysian consumers to understand. Private Browsing, available to all Safari users at no additional cost, provides more limited protections focused on preventing browsing history from being stored locally on the device. Private Relay, by contrast, requires an iCloud+ subscription—currently priced at 4.99 US dollars monthly—with the explicit promise of masking IP addresses and preventing websites from linking browsing activity to user identity. This vulnerability represents a failure to deliver on that specific premium promise, raising questions about the value proposition of the subscription service.

Bakry and Mysk have demonstrated appropriate responsible disclosure practices by notifying affected developers and organizations including the Tor Project and the developers of Onion Browser before publishing their findings publicly. They also updated their Psylo browser to implement protective measures against the identified flaws. However, the fact that individual app developers must patch vulnerability issues that stem from Apple's WebKit mandate highlights an asymmetry in the responsibility structure. Apple, which controls the mandatory browser engine and the App Store distribution mechanism, faces different accountability pressures than smaller developers.

Apple has not publicly responded to requests for comment regarding the vulnerability, including from technology publications investigating the discovery. This silence raises questions about the company's timeline for addressing these issues and whether affected users will receive notification about potential IP address exposure through their devices. For Southeast Asian users who depend on privacy protections to circumvent regional censorship or surveillance concerns, the lack of immediate public response from Apple regarding both the vulnerability and remediation plans represents a significant governance gap.

The practical implications for Malaysian and broader regional internet users deserve careful consideration. Many individuals in Southeast Asia rely on privacy tools like VPNs and privacy-focused browsers to access information freely and maintain personal security. The discovery that Apple's premium privacy feature contains fundamental flaws suggests that users cannot place complete trust in single platform providers' privacy promises without independent verification. This vulnerability underscores the importance of combining multiple privacy approaches and understanding the technical details of security features rather than relying solely on marketing claims from major technology corporations.