FACEPALM: Apple's iCloud Private Relay, the company's privacy-protecting service for Safari that comes with any paid iCloud+ plan, doesn't appear to be as private as Cupertino claims. A new report has revealed how attackers can learn a Private Relay user's real IP address, and many websites may already have collected the information. The same issue also affects the Onion Browser iOS app.

The discovery comes from security researchers Talal Haj Bakry and Tommy Mysk, who found three WebKit features that bypass application-level proxy settings: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. WebKit underpins Safari and, in most countries, every other browser available on iOS.

Private Relay isn't the same as a traditional VPN. When Safari traffic leaves the device, it is encrypted and sent through two relays, separating the user's IP address from the sites they visit so neither Apple nor its infrastructure partner sees both. Unlike a VPN, however, it does not tunnel every connection at the operating-system level. The service has previously faced opposition from European mobile carriers.

The most concerning leak involves WebAuthn, the standard behind passkeys. A webpage can trigger a Related Origin Request that Apple's credential service fetches directly from the device rather than through Safari.