Passkeys & iCloud Private Relay: Real IP Leak

Article Summary

  • Her iCloud Private Relay reveals your IP address when you visit websites that utilize passkeys technology.
  • The gap is due to the way WebKit and the WebAuthn standard handle requests, bypassing proxy servers.
  • A website can silently pull your real IP in the background, making them stand alone one-way street to absolute anonymity.

How IP leak via passkeys works

You pay for an iCloud+ subscription to have peace of mind with iCloud Private Relay, believing that Apple is keeping your real IP address away from prying eyes. But according to security researchers Tommy Mysk and Talal Haj Bakry , all it takes is one visit to a website that supports passkeys to blow the entire anonymity mechanism up.

The problem is not theoretical. As 404 Media reports , Apple is already investigating the issue following the revelations, which show that the service's architecture has fundamental blind spots when paired with modern authentication prototypes. If you want to check immediately if your device is exposed, the researchers have set up a special leak testing platform where you can run your own test.

Why WebKit bypasses Private Relay

The main pitfall lies in the difference in philosophy between a traditional VPN and Apple's Private Relay. While a VPN takes on the task of routing all of the operating system's network traffic, Apple's tool works mainly at the level of Safari and selected applications, hiding browsing requests behind two separate proxy servers.

Passkeys are based on the WebAuthn standard, which stores cryptographic keys locally on your device, not in your browser. When a website requests authentication, WebKit delegates the process to the native credentials service of iOS or macOS. According to an analysis by MacRumors , this means that the HTTPS request goes directly from the device to the destination server, bypassing the Private Relay proxy route entirely and revealing your real IP.

Stealth attacks and additional DNS leaks

What makes the situation worrisome is not just the leak itself, but the invisible way it can be exploited. An attacker can set an irregular parameter rpId and execute the request with the setting mediation: "conditional"Thus, the process takes place in the background without ever asking for any confirmation from you and without leaving a visual trace on the screen.

What's more, Mysk and Haj Bakry found that the problem isn't limited to passkeys. Features like DNS prefetching in iOS expose the actual DNS servers you're using, while newer features like WebTransport can also leak your real IP address. No matter how much protection you think the best mobile connections provide , local browser rendering engines often open backdoors.

Our opinion at TechNoid

We at TechNoid believe that Apple is once again creating a false sense of security with “semi-anonymity” services that charge extra but fail at the basics. iCloud Private Relay is great for hiding from casual trackers and advertisers, but it is not and should not be treated as a substitute for a serious VPN. Until Apple overhauls the way WebKit handles WebAuthn requests, the only reliable solution for those who require true IP hiding remains using a standalone, tested device-level VPN.

FAQ about IP Leaking in iCloud Private Relay

Does this issue affect users outside of Safari?

Yes, because the vulnerability stems from the way WebKit and system services work, some third-party browsers are also affected accordingly.

I need to do some to see it on the researchers' site?

Simply visit their test platform from your device with Private Relay enabled to see if the server detects your real IP.

Can a website steal my IP without me realizing it?

Absolutely. By using specific parameters in WebAuthn, the process runs completely silently in the background without any visual message on the screen.

Is iCloud Private Relay a full VPN?

No, it does not cover all of your device's network traffic nor does it work at the operating system level like a classic VPN.

Will Apple fix this security flaw?

The company has already officially stated that it is investigating the issue, however a structural change to the WebKit code is required to permanently close the hole.

Can I be temporarily protected until there is an official fix?

The safest option right now is to disable Private Relay and use a reliable third-party VPN service.

Are all versions of iOS affected by DNS leaks?

Newer mechanisms like DNS prefetching and WebTransport have been detected in recent versions of iOS, exposing additional connectivity data.

Dimitris Marizas
Dimitris Marizashttps://technoid.gr
I write about technology from the perspective of the person who uses it every day — not from conference rooms. I deal with networks, satellite internet, smartphones and digital services, with an emphasis on what these mean practically for the Greek user. Behind each article lies hours of analysis, testing and — when necessary — criticism of what the marketing tries to hide.

Related Articles

LEAVE A REPLY

enter your comment!
please enter your name here

- Advertisement -

Stay Connected

321SupportersLike
112FollowersFollow
231FollowersFollow
- Advertisement -

Most Popular 48hrs

- Advertisement -

Latest Articles