Apple's vaunted privacy protections may not be as robust as the company claims. Security researchers have uncovered significant vulnerabilities in Private Relay, Apple's premium privacy service bundled with iCloud+, that allow user IP addresses to leak onto the internet even when the feature is supposedly active and protecting communications.

The flaw emanates from three distinct bugs discovered in WebKit, the browser engine that Apple mandates all iOS browsers must use—a policy that means Safari, Tor Browser, and other privacy-focused applications share the same underlying vulnerability. Cybersecurity researchers Talal Haj Bakry and Tommy Mysk, who co-developed the privacy browser Psylo, published their findings in August after being alerted by a user who observed DNS leaks on certain websites. Their investigation revealed multiple pathways through which a device's genuine IP address could be exposed, fundamentally undermining the privacy guarantees that users paying for iCloud+ expected to receive.

The situation presents a peculiar irony in Apple's privacy architecture. Private Relay, introduced in 2021, operates through a two-relay system designed so that no single entity—not even Apple itself—can simultaneously know a user's identity and their browsing behaviour. The service essentially routes internet traffic through multiple intermediaries to obscure the connection between user and destination website. Yet this system contains a critical blind spot that manifests when users employ passkeys, which are increasingly promoted as a more secure alternative to traditional passwords. Because passkeys require devices to make authentication requests outside the browser environment, these requests bypass Private Relay entirely, exposing the device's actual IP address in the process.

For Malaysian users and others across Southeast Asia, this vulnerability carries particular weight. Internet protocol addresses function as digital identities that reveal approximate geographic location down to postal code level, enabling internet service providers, website operators, and other parties to monitor online activity patterns. In regions where internet monitoring and data collection practices remain less transparent than in developed markets, such exposure can have practical consequences for user autonomy and digital security. Furthermore, malicious actors regularly exploit exposed IP addresses to launch targeted cyberattacks, including distributed denial of service attacks and network-based intrusions that can compromise device security regardless of software protections.

The researchers coordinated their response with the Tor Project and Onion Browser developers, immediately pushing patches to Psylo to mitigate the identified flaws. However, the fact that all iOS browsers share the same underlying WebKit vulnerability means that Safari users and those using other privacy-focused applications remained exposed until Apple itself addressed the issue through system updates. This dependency on a single browser engine, while potentially beneficial for security consistency, creates a single point of failure when vulnerabilities emerge—a reality that particularly impacts users in markets where Apple devices command significant market share, as they do throughout Southeast Asia.

Apple's response to these revelations remains notably absent. The company did not provide comment when contacted about the vulnerability, a departure from its more forthcoming approach to other security matters. This silence contrasts sharply with Apple's public messaging around privacy, which has formed a cornerstone of the company's brand positioning and marketing strategy. In June, Apple launched an advertising campaign explicitly highlighting Safari's privacy advantages over competitors like Google Chrome, claiming superior protection against tracking and data collection. The company has consistently positioned itself as a privacy champion, introducing features like Intelligent Tracking Prevention as far back as 2017, which promised to shield user IP addresses from third-party trackers.

For Southeast Asian consumers who have adopted Apple's ecosystem partially on the strength of these privacy assurances, the discovery of these flaws raises fundamental questions about the company's security architecture and quality assurance processes. Private Relay represents a premium service that iCloud+ subscribers pay extra to access, making them particularly reliant on Apple's claims about the feature's effectiveness. When that protection fails silently, without user knowledge or control, it represents not merely a technical oversight but a breach of the trust relationship between Apple and its paying customers.

The distinction between Apple's various privacy features also requires clarification for users seeking to protect themselves. Private Browsing, a separate feature that Apple describes as providing additional privacy protections for individual browser tabs, does not save browsing history but offers fundamentally different protections than Private Relay. Many users conflate these features, assuming that browsing privately automatically masks their IP address, when in fact Private Relay requires separate subscription and activation. This complexity in Apple's privacy feature architecture may itself contribute to user confusion about what level of protection they actually possess.

The WebKit vulnerability highlights a structural challenge in modern device security: the tension between mandating consistent technical standards and preventing security monocultures. By requiring all iOS browsers to use WebKit, Apple ensures uniform security updates and consistent performance characteristics. However, when vulnerabilities emerge in WebKit itself, every browser on the platform becomes simultaneously exposed, and users cannot simply switch to alternative browsers using different rendering engines as they might on Android or desktop platforms. This architectural constraint means that iPhone and iPad users dependent on Private Relay for security have limited recourse until Apple patches the underlying issue through iOS updates.

For regional technology observers and privacy advocates, this situation underscores the importance of independent security research and transparent vulnerability disclosure. Researchers like Bakry and Mysk play a critical role in uncovering flaws that manufacturers might otherwise downplay or delay addressing. Their willingness to publicize findings about Private Relay's shortcomings, despite Psylo's own dependence on functioning privacy protections, demonstrates a commitment to user security that sometimes conflicts with commercial interests. As consumers throughout Southeast Asia increasingly adopt premium digital security measures, the accountability mechanisms that catch and publicize such vulnerabilities become essential safeguards.