← Home
GADGETS

Apple’s Private Relay Found to Leak Real IP Addresses, Affecting OnionBrowser

August 12, 2026 Marcus Reeves

WebKit flaws that betray user anonymity

Security researchers have uncovered three flaws in Apple’s WebKit engine that can reveal the true IP addresses of users employing the Private Relay service. The vulnerabilities also impact OnionBrowser, an iOS application that routes traffic through the Tor network.

Private Relay, a feature of i Cloud+, is intended to mask a user’s location by routing traffic through two encrypted relays. The newly identified bugs bypass this design, allowing websites to capture the original IP through crafted web content. Apple acknowledged the issue on August 5 and said its engineering team is actively reviewing the findings. Meanwhile, several browser developers have already released patches to mitigate the exposure.

The three vulnerabilities stem from how WebKit processes certain JavaScript calls and network requests. When a malicious page triggers these calls, the browser inadvertently leaks the device’s external IP before the relay can mask it. Researchers Talal Haj Bakry and Tommy Mysk demonstrated the exploit using a simple test page hosted on a public server. Their proof‑of‑concept showed that the real address could be logged within milliseconds of page load.

Will Private Relay remain a reliable privacy tool?

Apple’s security bulletin describes the bugs as „high severity” and promises a software update in the upcoming iOS release. In the meantime, developers of alternative browsers, including OnionBrowser, have introduced temporary workarounds that block the offending scripts. These measures reduce the risk but do not fully restore the privacy guarantees originally marketed by Private Relay.

Experts warn that the incident may erode confidence in Apple’s privacy promises, especially as regulators scrutinize data‑handling practices. If the flaws persist, malicious actors could combine the IP leak with fingerprinting techniques to track users across sites. Apple’s swift investigation and forthcoming patch could mitigate immediate threats, but the episode highlights the difficulty of securing complex web stacks. Users may need to rely on additional layers, such as VPNs or Tor, until the system is proven robust.

The disclosure underscores the fragile nature of built‑in anonymity tools and may prompt broader industry audits of similar services. Apple could face pressure from privacy advocates to adopt more transparent disclosure practices and faster rollout of security fixes. For consumers, the episode serves as a reminder to stay vigilant and consider

Read full article on Tech Site News →