VC
Value Add VC
⚡HomePulse⚡Helpful Apps📝Blog🤝Partner
Illustration for: Apple's Private Relay Is Leaking Real IP Addresses
Value Add VC/Pulse/BIG TECH

Apple's Private Relay Is Leaking Real IP Addresses

Researchers Tommy Mysk and Talal Haj Bakry published three WebKit flaws that let websites see an iCloud+ subscriber's real IP address even with Private Relay switched on, and say they skipped disclosing to Apple first.

By the Numbers

3
WebKit flaws disclosed
Aug 5, 2026
Disclosure date
Mysk + Haj Bakry
Researchers
iCloud+ paid only
Feature tier
All iOS browsers
Browsers affected
TC
Trace Cohen
Early-stage VC & angel · Founder, New York Venture Partners
August 5, 2026
3 min read
ShareXLinkedInEmail

THE RUNDOWN

1

Private Relay is the marquee privacy feature Apple sells inside iCloud+, and the researchers' test site shows it can be bypassed from ordinary web pages

2

One bypass runs through passkeys: the WebAuthn credential request is issued by the operating system's credential service, not by Safari, so it never enters the proxied path

3

Because Apple requires every iOS browser to use WebKit, the flaws hit every browser on iPhone and iPad -- including OnionBrowser, the Tor-style browser for iOS

4

The researchers went public without a private report first, saying prior Apple disclosures meant months of delay and, at times, denial of impact

TC

The VC Read · Trace's Take

Trace Cohen

Every consumer privacy startup pitching me says "we're like Private Relay but better." Now the comp has a public bug. The diligence item is specific: ask any privacy product where it interposes -- browser process, OS network extension, or DNS -- and make them name what traffic escapes that layer. Private Relay is Safari-scoped in an OS that keeps moving work out of Safari, and that gap is structural, not a one-off bug. Also note the researchers skipped Apple entirely. When your platform partner's security response is slow enough that researchers stop calling you first, that's a risk on your roadmap too.

Big Tech Earnings →

Analysis

Security researchers Tommy Mysk and Talal Haj Bakry published a set of three WebKit flaws on Tuesday that let a website recover the real IP address of an iCloud+ subscriber who has iCloud Private Relay enabled, according to [404 Media](https://www.404media.co/apples-private-relay-is-exposing-users-real-ip-addresses/), which first reported the findings. The pair built a live test page that demonstrates the bypass rather than describing it in the abstract. Apple told 404 Media it was investigating the report and did not commit to a fix timeline; [TechCrunch](https://techcrunch.com/2026/08/05/psa-apples-private-relay-can-leak-your-real-ip-address/) said Apple did not immediately respond to its own request for comment.

The cleanest of the three paths runs through passkeys. When a site initiates a WebAuthn authentication, the credential request is issued by the operating system's credential service rather than by Safari itself. Private Relay only proxies Safari's own traffic, so the credential fetch leaves the device on the ordinary network path and the destination server sees the subscriber's actual address. Nothing about the flow looks broken to the user -- the padlock, the Private Relay toggle, and the sign-in all behave normally.

Private Relay shipped in 2021 as a paid iCloud+ feature and has always carried a narrower promise than a VPN: it masks IP and DNS only inside Safari, not system-wide. That narrower scope is exactly what makes these flaws awkward. The bypasses live in the seam between Safari and the rest of iOS, and because Apple's App Store rules require every iOS browser to render with WebKit, there is no third-party browser on iPhone that escapes them. OnionBrowser, the Tor-oriented browser for iOS, is affected; the desktop Tor Browser is not.

“Private Relay shipped in 2021 as a paid iCloud+ feature and has always carried a narrower promise than a VPN: it masks IP and DNS only inside Safari, not system-wide.”

The disclosure process is its own story. Mysk and Haj Bakry said they did not report privately first, citing past experience of "months of delays, inconsistent communication, and in some cases, denying the issue's impact entirely." That is an unusual position for researchers with a long Apple track record, and it puts pressure on Apple's security response process as much as on WebKit. It is also the second privacy-feature failure the same researchers have surfaced recently, following a Hide My Email flaw that exposed real addresses.

For anyone building privacy-branded products, the useful lesson is architectural rather than reputational. Private Relay is a browser-scoped proxy in an operating system where an increasing share of network activity -- credential services, push, app-initiated fetches, system telemetry -- happens outside the browser process. Every feature Apple moves out of Safari and into the OS layer widens the surface that a Safari-scoped proxy cannot cover. Competing consumer VPNs from Cloudflare, Proton, and Mullvad interpose at the network layer instead, which is slower and heavier but does not have this class of gap.

The counterweight: this is an IP-address exposure, not an account compromise, and it requires a site that is deliberately looking. No evidence has been published that anyone exploited it in the wild, and the practical harm to a typical user is closer to "an ad network correlated your session" than to a breach. Apple can also close the passkey path server-side in the credential service without a full WebKit rewrite. Treating this as a catastrophic failure overstates it; treating it as cosmetic understates how much Apple charges for the promise.

What to watch: whether Apple ships a fix in the next iOS point release or waits for a major version, and whether it changes its posture toward researchers who bypass private disclosure. If public-first disclosure becomes the norm for Apple privacy features, the company's security-response reputation becomes a product problem, not just a PR one. Watch, too, for whether any regulator in the EU picks this up -- Apple markets Private Relay as a privacy protection people pay for, and a paid feature that underdelivers is the kind of claim consumer-protection authorities have taken up before.

ShareXLinkedInEmail

More on

Apple →

Analysis and editorial commentary by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.

Read Next

BIG TECH· Aug 5, 2026

Saudi PIF, Kushner's Affinity Close $55B EA Buyout

Illustration for: Saudi PIF, Kushner's Affinity Close $55B EA Buyout
BIG TECH$55B buyout

Saudi PIF, Kushner's Affinity Close $55B EA Buyout

A consortium led by Saudi Arabia's PIF, Silver Lake and Jared Kushner's Affinity Partners completed a $55B take-private of Electronic Arts, financed by a $20B JPMorgan loan -- the largest leveraged buyout on record.

BIG TECH· Aug 5, 2026

AMD Sinks Despite Record Earnings, Data Center Doubles

Illustration for: AMD Sinks Despite Record Earnings, Data Center Doubles
BIG TECH$11.5B Q2 revenue

AMD Sinks Despite Record Earnings, Data Center Doubles

AMD posted record $11.5B quarterly revenue and 107% data center growth, yet shares fell nearly 9% after hours as investors questioned the pace and durability of the AI buildout funding it.

BIG TECH· Aug 4, 2026

SpaceX Now Makes More Money as an AI Company

Illustration for: SpaceX Now Makes More Money as an AI Company
BIG TECH

SpaceX Now Makes More Money as an AI Company

SpaceX's Q2 revenue nearly doubled year-over-year, with compute deals for Anthropic and Google now contributing enough that its AI-infrastructure business is rivaling its core launch and Starlink revenue.

@Trace_Cohen·t@nyvp.com