Skip to main content
  1. Home
  2. Phones
  3. News

Apple’s iCloud Private Relay isn’t as private as you think

Your real IP address might be leaking, and passkeys are the snitch.

Add as a preferred source on Google
iCloud Private Relay
Rachit Agarwal / Digital Trends

If you pay for iCloud+ and rely on Private Relay to hide your IP address while browsing, you might want to pay attention to this one. New research by security researchers Tommy Mysk and Talal Haj Bakry, first reported by 404 Media, reveals that Private Relay doesn’t hide your IP address as well as Apple claims.

How does the leak actually happen?

Private Relay is supposed to route your Safari traffic through a two-hop relay so nobody, not even Apple, can connect your identity to the sites you visit. The problem lies in how passkeys work. When a website asks your device to verify a passkey, your iPhone’s credential service fetches the validation file directly, bypassing Safari and Private Relay. Since the request never touches your browser’s protected traffic, the website receiving it sees your real IP address instead of the relay’s.

Mysk explained the scope of the issue plainly, telling 404 Media that “any website that supports, or pretends to support, passkeys” can access this information, even with Private Relay switched on. The researchers also noted in their own research post that because the fetch comes from the “device’s real IP address either way,” there is currently no way around it while using Safari with Private Relay turned on.

Should you be worried?

This isn’t the first privacy hiccup for Apple’s paid iCloud+ features either. Just last month, it was reported that Apple’s Hide My Email tool was quietly exposing users’ real email addresses, a bug the company reportedly knew about for over a year before fixing it.

Recommended Videos

The silver lining here is that regular VPNs are not affected, since they encrypt your entire device’s traffic at the system level instead of just your browser. If you use Private Relay for anything sensitive, it might be worth switching to a full VPN until Apple sorts this out. Apple has told 404 Media that it is looking into the researchers’ findings, so hopefully a fix isn’t too far away.

Rachit Agarwal
Rachit is a seasoned tech journalist with over ten years of experience covering the consumer technology landscape.
WhatsApp is making it easier for channel admins to label AI-generated posts
Because not every photo in your favorite channel is as real as it looks.
WhatsApp app store listing open on iPhone

WhatsApp already lets channel admins mark sponsored posts with a paid partnership label, a feature that started rolling out last month on Android and iOS. Now the app is cooking up something similar, but this time for AI-generated media. The idea is to keep followers in the loop when a photo or video wasn't captured with a camera but conjured up by an AI tool instead.

How will the new AI label work?

Read more
Meta served ads containing AI-generated child sexual abuse content, continuing years of child safety failures
Meta's own ad library hosted child abuse imagery for nine months straight.
meta-logo

Meta's ad platform did something it has promised, repeatedly, never to allow again. According to a new investigation from Wired, Meta ran dozens of paid ads over the past nine months containing explicit AI-generated child sexual abuse imagery, some of which stayed live even after the company was directly confronted about them.

If this feels like a story you've read before, that's because you probably have. Just weeks before this latest report, a separate BBC investigation found Instagram running paid ads promoting child sexual abuse material in India, directing users to Telegram channels selling illegal content.

Read more
This new technology could make spotting fake products easier for everyone
Your smartphone could soon tell you if the product you bought is fake
The new system combines three technologies into a single printable label.

Counterfeit goods are becoming increasingly sophisticated, forcing brands to rely on expensive authentication systems that often require specialized scanners or proprietary hardware. Researchers now believe a smartphone could do much of that work instead. A team has developed a new printing system that creates responsive anti-counterfeit labels that are more durable, easier to mass-produce, and can be verified using nothing more than a phone. The research was published in the International Journal of Materials and Product Technology.

At first glance, the technology looks like another incremental improvement in product security. In reality, it addresses one of the biggest limitations of anti-counterfeit systems today: accessibility. If authentication only works with expensive equipment, it becomes difficult to deploy at scale. By enabling smartphone-based verification, the technology could make counterfeit detection practical for manufacturers, retailers, and even consumers.

Read more