Security researchers discovered flaws in Apple’s iCloud Private Relay service. The vulnerability exposes real user IP addresses, defeating the feature's primary purpose of masking locations. The issue originates in WebKit, the browser engine powering Safari and all third-party browsers on iOS.

Certain WebKit functions bypass the Private Relay proxy, specifically requests related to the WebAuthn standard for passkeys. Websites supporting or simulating passkeys can trigger these requests to reveal a user’s actual IP address.

The leak impacts iCloud Private Relay and other privacy-focused iOS applications relying on WebKit. Affected software includes the OnionBrowser for the Tor network.