
Security Flaw in Apple’s iCloud Private Relay Exposes Users’ Real IP Addresses
CybersecurityVulnerabilitiesPrivacyWebSecurity
Cybersecurity researchers disclosed a security issue in Apple’s iCloud Private Relay tool that can expose a user’s real IP address. The feature, introduced with iOS 15, uses a dual-hop architecture to route Safari web traffic through two relays, preventing any single third party—including Apple—from identifying the request’s origin. The vulnerability stems from WebKit proxy bypasses, which undermine the privacy protections of the relay system. No specific CVE ID, patch date, or affected version range beyond iOS 15 was mentioned in the report. The impact involves potential deanonymization of users relying on iCloud Private Relay for privacy.