Apple's much-touted privacy protections are facing fresh scrutiny after cybersecurity researchers uncovered significant vulnerabilities in the company's WebKit browser engine that can expose user IP addresses—precisely what Apple claims to protect against. The discovery represents a troubling gap in one of the technology giant's flagship privacy features, Private Relay, which is offered as a premium addition to iCloud+ subscriptions. The findings were published in early August by researchers Talal Haj Bakry and Tommy Mysk, who identified three distinct flaws that allow devices to leak both domain name system information and real IP addresses, undermining the privacy protections that users have paid for.
The vulnerability stems from a systemic architectural issue within WebKit, the browser engine that Apple mandates all iOS applications must use. Because of this App Store requirement, no iOS browser—whether Safari, alternative privacy-focused options, or even Tor browsers—can bypass WebKit's limitations. This creates a blanket vulnerability affecting the entire iOS ecosystem. The researchers discovered the problem while investigating why their privacy-focused Psylo browser was leaking DNS information on certain websites. What began as debugging a single application led them to identify broader weaknesses that compromise the integrity of Apple's own Private Relay system.
The situation is particularly ironic because the flaw emerges from the interaction between Private Relay and another security feature that Apple designed to enhance user protection: passkeys. These authentication credentials represent a modern alternative to traditional passwords, offering superior security against phishing and credential theft. However, when users attempt to log in using passkeys, their devices must send requests outside the normal browser process. This architectural requirement means passkeys bypass Private Relay's protective tunnelling system entirely, exposing the user's actual IP address to the websites receiving the authentication request. Users who believed they were fully protected while using Private Relay are inadvertently broadcasting their location and device information in the very moment they are attempting to secure their accounts.
Understanding why IP address exposure matters requires recognising the multiple privacy and security threats that these numerical identifiers present. Internet protocol addresses function as digital home addresses, pinpointing a user's approximate geographic location down to postal code level. This information becomes valuable to internet service providers, website operators, and advertising networks seeking to track browsing behaviour and target users with location-specific content. Beyond commercial tracking, malicious actors exploit IP addresses to launch directed cyberattacks, identify targets for harassment, or conduct reconnaissance against individuals or organisations. For journalists, activists, and others in repressive regions, IP address exposure can carry serious physical consequences.
Apple has built considerable brand equity around privacy commitments, positioning its devices and services as fundamentally more protective of user data than competitors. The company spent considerable resources in June promoting Safari's privacy advantages over Chrome and other browsers, emphasising features like Intelligent Tracking Prevention, which it introduced in 2017. Private Relay, launched in 2021, represents the logical evolution of these efforts, using a two-hop relay system designed to ensure that no single entity—not even Apple itself—can simultaneously observe both a user's identity and their browsing destinations. This architectural approach represented a sophisticated privacy solution that distinguished Apple from competitors. The new vulnerabilities suggest that the implementation fell short of the ambitious design.
The researchers' responsible disclosure process demonstrates the importance of coordinated security research. Beyond notifying Apple, Bakry and Mysk alerted the Tor Project and Onion Browser developers, whose privacy-focused users depend absolutely on anonymity protections. They also updated Psylo to mitigate the identified flaws, showing how independent developers must compensate for vulnerabilities in the underlying platform. This raises uncomfortable questions about the extent to which iOS developers can ensure user privacy when fundamental architectural constraints prevent them from fully implementing their intended protections.
For Malaysian users and Southeast Asian readers more broadly, these findings carry particular relevance. Across the region, concerns about digital surveillance, government monitoring, and corporate data harvesting are rising. Activists, journalists, and ordinary citizens increasingly rely on privacy tools precisely because surveillance threatens accountability and individual liberty in contexts where institutional safeguards may be inadequate. When premium privacy features fail to work as advertised, users in Malaysia, Hong Kong, Thailand, and elsewhere cannot be confident that their communications remain private. The discovery also highlights how technology companies' design decisions in distant headquarters affect the security of dissidents, minorities, and vulnerable populations in countries where privacy is not routinely protected.
Apple's silence on the matter is notable. The company has not responded to requests for comment regarding the vulnerabilities or its plans to address them. This lack of transparency stands in tension with Apple's public positioning as a privacy champion. Users who subscribed to Private Relay because they trusted Apple's privacy claims deserve clear communication about the scope of the vulnerability, which devices and situations are affected, and what timeline the company intends for remediation. Without such transparency, Apple risks further eroding the credibility that underpins its premium market positioning.
The incident also raises systemic questions about the iOS ecosystem's architecture. Apple's requirement that all browsers use WebKit, ostensibly to maintain security and performance standards, creates a monolithic vulnerability landscape where flaws in the core engine cannot be worked around or patched independently by competing applications. In contrast, Android's openness allows users and developers to choose alternative browsers with different engines, providing redundancy if vulnerabilities emerge in any single implementation. While Apple's controlled approach offers genuine security benefits in many respects, it also concentrates risk in a way that becomes apparent when critical flaws are discovered.
Moving forward, Apple faces pressure to address these vulnerabilities comprehensively while also confronting deeper architectural questions about how to balance its closed ecosystem model with genuine privacy protection. Users who trusted Apple's privacy promises, particularly those paying for premium iCloud+ subscriptions, are left in an uncomfortable position: should they continue relying on features that have proven unreliable, or should they adopt supplementary privacy tools that add layers of protection independent of Apple's systems? The answer will likely depend on Apple's response—both in terms of technical remediation and in restoring user confidence through transparent communication about what went wrong and how it will prevent similar vulnerabilities in the future.
