Spreely +

  • Home
  • News
  • TV
  • Podcasts
  • Movies
  • Music
  • Social
  • Shop
  • Advertise

Spreely News

  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports
  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports
Home»Spreely News

Apple ICloud Private Relay Leaks May Expose Real IP Address

Kevin ParkerBy Kevin ParkerAugust 16, 2026 Spreely News No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

iCloud Private Relay is built to hide the details websites normally use to pin down a visitor, but fresh research shows that promise is not airtight. Security researchers found three WebKit paths that can slip around the relay, potentially exposing a real IP address or DNS-related information during ordinary browsing.

That matters because the leaks do not depend on shady downloads or obvious malware. They involve standard browser features that can fire quietly in the background, which makes the privacy gap more unsettling than a typical attack.

Private Relay is meant to split the browsing trail so no single party can see both the user and the destination. When it works as intended, Safari traffic gets an extra privacy buffer that blocks websites from seeing the real IP address and precise location tied to a connection.

The trouble starts with WebKit, the browser engine behind Safari and other apps that rely on Apple’s browsing stack. The researchers say DNS prefetching, WebAuthn and WebTransport each create a separate route where network information can escape the relay and travel a more direct path.

DNS prefetching is supposed to help pages load faster by resolving addresses before a click even happens. In this case, the researchers found that those requests can bypass the relay and use the device’s normal DNS connection instead, which can reveal where the request is really coming from.

The second issue centers on WebAuthn, the standard behind passkeys. Some services need to check whether related domains belong to the same organization, and that verification can trigger a direct request that exposes the device’s real IP address even while Private Relay remains switched on.

That does not mean passkeys themselves are broken or easy to steal. The concern is narrower but still important: a verification step tied to passkey use can create a privacy leak without changing the actual security of the passkey system.

WebTransport adds a third wrinkle. It is designed for fast, low-latency connections that help interactive web apps feel smoother, but researchers found it can also open a direct connection from the device instead of moving through the proxy path Private Relay is supposed to control.

See also  World's First Solar-Powered Ambulance Brings Care Off-Grid

For people who count on Safari privacy features, the impact is broader than it first sounds. The researchers looked at WebKit-based proxy browsers on iOS and macOS, which means the issue is not limited to one small corner of Apple’s ecosystem.

That also explains why a standard VPN behaves differently. A VPN tunnels traffic at the system level, while Private Relay depends on browser-level routing, so these specific WebKit leaks do not affect the same way when the entire device traffic is wrapped in a VPN connection.

Still, a VPN is not a magic cloak. Websites can continue to recognize people through logins, cookies and other fingerprints, so the bigger lesson is that no single privacy tool covers every angle.

For most users, the right response is not panic. Private Relay still protects a lot of Safari browsing, and it is better than going without any relay at all, but it should be understood as one layer of defense rather than the final word on anonymity.

Keeping Apple devices updated remains smart, since fixes for privacy issues often arrive through software releases. If a browser or operating system patch closes these paths later, that update could matter a lot more than any quick setting change.

People who care deeply about hiding their IP address may want to think about a full-device VPN for sensitive browsing. In that scenario, the system-wide tunnel offers a different kind of protection than a browser-only relay, especially when the goal is to keep network details out of reach.

Passkeys still deserve a place in the security toolbox. Even with this finding, they remain a strong defense against phishing and password theft, and the privacy leak described by researchers does not turn them into a weak link.

Browser developers are clearly paying attention too. Psylo has already adjusted its browser behavior by blocking DNS prefetch hints and disabling WebTransport and WebAuthn by default, showing that these gaps can be narrowed when the software side takes the issue seriously.

The bigger takeaway is simple enough: privacy features are only as good as the paths they actually cover. A setting can look reassuring in the menu, yet a hidden browser behavior can still let a few important details slip through the cracks.

Technology
Avatar photo
Kevin Parker

Keep Reading

Americans Clash Over Transgender Athletes As Sports Debate Heats Up

Pennsylvania Medicaid Fraud Bust Sparks Minnesota-Style Alarm

World’s First Solar-Powered Ambulance Brings Care Off-Grid

Expert Reveals Ways To Reignite Intimacy In Sexless Marriages

Loneliness Study Finds One In Six Adults Still Struggling

Shannon Watts Torches Hasan Piker Over Controversy Playbook, Says It’s Bats Crazy

Add A Comment
Leave A Reply Cancel Reply

All Rights Reserved

Policies

  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports
  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports

Subscribe to our newsletter

Facebook X (Twitter) Instagram Pinterest
© 2026 Spreely Media. Turbocharged by AdRevv By Spreely.

Type above and press Enter to search. Press Esc to cancel.