Apple’s iCloud Private Relay can expose an iPhone user’s real IP address through WebAuthn and WebTransport requests that escape its relay path, according to research published on 4 August 2026. A third route, DNS prefetching, sends queries through the device’s normal DNS path. Apple told 404 Media it is investigating the findings.Security researchers Talal Haj Bakry and Tommy Mysk identified the three WebKit behaviours while examining traffic from Psylo, their proxy-based privacy browser. Their says WebAuthn Related Origin Requests can expose the device’s real IP from iOS 18, DNS prefetching can reveal its normal resolver path from iOS 26, and WebTransport can open a direct connection from iOS 26.4. reproduced the IP disclosure with the researchers’ test page.About The AuthorAshna is a content writer who focuses on making everyday choices easier and smarter. With a strong eye for detail and a natural sense of what works in real life, she creates content that feels honest, relatable, and genuinely helpful. She is a geek for writing stories around fashion, beauty, and influential products, while bringing the same depth and detail in reviewing tech products and gadgets of day-to-day use.
Apple’s Private Relay Has Two IP Leaks Plus DNS Exposure
Recent findings indicate that Apple's iCloud Private Relay has inadvertently exposed the actual IP addresses of iPhone users. Researchers pinpointed three methods—WebAuthn, WebTransport, and DNS prefetching—that sidestep the intended privacy protections. Apple's team is actively examining these vulnerabilities. For users seeking comprehensive IP masking across their devices, employing a system-level VPN is recommended for heightened privacy.










