Apple’s Private Relay, an opt-in iCloud+ feature designed to mask a user’s IP address from the sites they visit in Safari, can be circumvented to reveal that supposedly hidden address due to a series of flaws in how the feature is implemented, according to a blog post published Tuesday by security researchers Talal Haj Bakry and Tommy Mysk. TechCrunch independently verified the leak using a testing site the researchers built. Researchers choosing not to report a privacy bug to the company whose product it affects, before publishing it, is what NewsTrackerToday banks to as the more unusual decision than the vulnerability itself.
The researchers traced the problem to three separate features inside WebKit, the browser engine Apple requires every browser on iOS to use, meaning the flaw isn’t confined to Safari specifically but touches any iOS browser built on Apple’s required engine. Private Relay only functions while using Safari and operates differently than a traditional VPN, which masks a user’s IP address at the system level regardless of which app or browser is generating the traffic.
Sophie Leclerc, who covers the technology sector, reads the WebKit-level nature of the bug as the more structurally important detail: “A flaw sitting inside WebKit itself, rather than inside Private Relay’s own relay logic specifically, means the vulnerability touches the shared foundation every iOS browser is built on, not just Apple’s own privacy feature. That’s a meaningfully harder category of bug to fully contain, since fixing it requires changes to infrastructure every third-party browser on iOS also depends on, not just a patch to one feature in one app.” That shared-infrastructure exposure, more than Private Relay’s specific failure, is what NewsTrackerToday keys to as the more consequential scope of this bug.
Mysk explained the decision not to report the issue to Apple before publishing in blunt terms on a post on X: “our past experience with Apple tells us that reporting this issue would involve months of delays, inconsistent communication, and in some cases, denying the issue’s impact entirely.” Apple did not immediately respond to a request for comment on the vulnerability itself or on the researchers’ stated reasoning for skipping the standard private-disclosure process.
Daniel Wu, who covers geopolitics and energy, reads the disclosure-norms question this raises beyond this single bug: “Coordinated disclosure, privately reporting a vulnerability before publishing it, exists specifically to give a company time to patch a flaw before it’s public and exploitable at scale. Researchers publicly bypassing that norm, citing a vendor’s own track record on responsiveness, is a real indictment of that track record, whether or not it holds up in this specific case. It also sets a precedent that could shape how other researchers handle future Apple vulnerabilities if they’ve had similarly frustrating experiences.” That precedent-setting choice, more than the technical bug itself, is what News Tracker Today ties round as the more significant story about how security research and large vendors are relating to each other right now.
Mysk and his colleagues also develop Psylo, a privacy-focused browser, and said it already includes mitigations preventing this exact IP-leak issue from affecting its own users, a detail that positions their public disclosure alongside a competing product built to avoid the flaw they’re describing in Apple’s implementation.
None of this confirms when or whether Apple issues a fix for the underlying WebKit flaws, since the company hasn’t publicly acknowledged the vulnerability at all as of this report. Whether Apple’s response to this public disclosure moves faster than the delayed pattern the researchers described experiencing in the past, or whether this becomes another case where a disclosed vulnerability sits unaddressed for months while iCloud+ subscribers unknowingly use a privacy feature that isn’t fully doing its job, is what NewsTrackerToday wraps round as the real question this disclosure leaves open.