Apple's much-promoted privacy protections have come under scrutiny following the discovery of a significant vulnerability that defeats one of its flagship privacy tools. Security researchers have uncovered flaws in WebKit, the browser engine that Apple mandates for all iOS browsers, which can leak user IP addresses—the unique identifiers that reveal a device's location and enable tracking—even when subscribers have activated Private Relay, Apple's premium privacy feature bundled with iCloud+.
The vulnerability was publicly disclosed on 4 August by Talal Haj Bakry and Tommy Mysk, a cybersecurity research and app developer team, after they traced DNS leaks affecting their own Psylo private browser. Their investigation uncovered not one but three distinct flaws within WebKit's architecture that expose real device IP addresses under certain conditions. The ramifications extend beyond their single application; the researchers found that since Apple's App Store policy compels all iOS browsers to use WebKit, every privacy-focused browser on the platform—including Tor browsers and others designed specifically to protect anonymity—inherits the same vulnerability.
The flaw represents a particularly ironic security failure because it emerges from the interaction between Private Relay and another Apple security feature. When users authenticate using passkeys, Apple's recommended replacement for traditional passwords, their devices must initiate requests outside the normal browser process to complete authentication. This architectural necessity bypasses Private Relay's protective double-relay system entirely, creating a direct pathway from the user's device to the internet without privacy intermediaries. For users who believe their iCloud+ subscription is protecting them, this gap represents a serious breach of the service's core promise.
Understanding what Private Relay was designed to accomplish clarifies why this flaw matters. Introduced in 2021, the feature employs a sophisticated two-relay architecture intended to ensure that no single party, including Apple itself, can simultaneously observe both a user's identity and their browsing destinations. The system works by routing traffic through multiple servers that separate identity information from activity logs. However, the passkey vulnerability undermines this separation by forcing identity verification outside the protective tunnel, exposing the originating IP address in the process.
IP addresses function as digital locations for internet-connected devices, revealing approximate geographic position down to postal code precision and enabling internet service providers, website operators, and other entities to build detailed profiles of user behaviour. Malicious actors routinely exploit IP information to orchestrate targeted cyberattacks or launch denial-of-service assaults. For individuals in Malaysia and across Southeast Asia where internet surveillance and data harvesting remain persistent concerns, IP address concealment serves as a foundational privacy protection. The exposure undermines not only individual privacy but potentially the security of activists, journalists, and others engaged in sensitive online activity.
Apple has invested heavily in cultivating a premium brand identity centred on privacy and security. The company launched a substantial advertising campaign in June emphasizing Safari's superior privacy protections compared with competitors like Chrome. This marketing positioning reaches back to 2017, when Apple introduced Intelligent Tracking Prevention, an earlier privacy mechanism designed to hide user IP addresses from tracking systems. Private Relay represented an evolution of this philosophy, promising comprehensive protection for premium subscribers willing to pay for iCloud+ membership. The discovery of these fundamental flaws in such a prominently featured service raises questions about the depth of security review applied to privacy-critical features.
The distinction between Private Relay and Safari's separate Private Browsing feature often confuses users, potentially amplifying the vulnerability's impact. Apple describes Private Browsing as offering enhanced privacy protections for individual browser tabs, primarily by preventing local history storage. This is fundamentally different from Private Relay's network-level protection, yet marketing terminology sometimes blurs this distinction. A user might activate Private Browsing believing they enjoy comprehensive privacy protection, when in fact they lack the network-level anonymity that Private Relay theoretically provides. Meanwhile, Private Relay subscribers may remain unaware that ordinary authentication processes are circumventing their protection.
Responding to their discovery, Baj Bakry and Mysk updated their Psylo browser to mitigate the specific flaws they identified, demonstrating that workarounds are technically feasible. They also notified the Tor Project and Onion Browser developers, expanding the circle of security-conscious projects now aware of the vulnerability. This coordinated disclosure approach reflects responsible security research practices, allowing affected parties time to develop patches before public disclosure generates widespread alarm. However, the fact that the vulnerability required external researchers to identify rather than Apple's internal security teams raises questions about the robustness of privacy feature testing.
Apple has not publicly responded to requests for comment on the vulnerability or its timeline for addressing the underlying WebKit flaws. This silence is notable given the company's investment in privacy marketing and the significant technical sophistication required to develop robust privacy solutions. For Malaysian users and Southeast Asian technology consumers more broadly, the episode illustrates that premium pricing and aspirational marketing claims warrant sceptical scrutiny. Privacy protections demand rigorous, ongoing security verification rather than promotional assertion alone.
The broader implications extend to ecosystem dynamics within Apple's locked iOS environment. By mandating WebKit usage, Apple maintains unified control over the browser layer but simultaneously creates a single point of failure for privacy-critical functionality. If WebKit contains vulnerabilities, every browser on iOS inherits them, regardless of the developer's security expertise or privacy commitments. This architecture contrasts with Android's more permissive approach, where browsers can employ alternative engines. The discovery suggests that centralized control, while enabling platform-wide security coordination, can also create concentrated risk when vulnerabilities slip through review processes.
For iCloud+ subscribers in Malaysia and the region, practical security responses remain limited until Apple patches these WebKit flaws. Users concerned about IP address exposure should assume that passkey-based authentication may circumvent Private Relay protection and consider additional anonymization tools like VPN services as supplements rather than relying solely on Apple's built-in protections. The vulnerability also serves as reminder that no single privacy tool provides absolute protection; layered approaches combining multiple technologies offer more robust defence than dependence on any single feature, regardless of vendor claims.
