Apple's iCloud Private Relay, the privacy tool built into iOS 15 and later, contains a WebKit vulnerability that allows attackers to bypass its dual-hop proxy architecture and expose users' real IP addresses, cybersecurity researchers disclosed this week.

iCloud Private Relay routes Safari traffic through two separate relays, preventing any single entity from linking a user's identity to their browsing activity. The dual-hop design ensures that Apple cannot see the destination site, while the destination site cannot see the user's real IP address. This design was central to Apple's privacy marketing for the feature.

The disclosed vulnerability exploits weaknesses in WebKit's proxy handling mechanisms. Researchers demonstrated that attackers can craft malicious websites to trigger requests that bypass the protective relay chain, directly exposing the visitor's real IP address to the attacker. The flaw does not require user interaction beyond visiting a compromised or attacker-controlled site.

The vulnerability affects iCloud Private Relay across supported devices and operating systems where the feature remains enabled. Users relying on iCloud Private Relay for location privacy during web browsing face reduced protection. Organizations whose employees use iCloud Private Relay may also face IP exposure in their network traffic logs, potentially revealing employee locations or work-from-home setups.

Apple users have several immediate options. Disabling iCloud Private Relay through Settings eliminates the false sense of protection, though this removes privacy benefits for all web traffic. Using a third-party VPN service provides alternative privacy protection, though this introduces different trust assumptions. Safari users can also limit their browsing to HTTPS sites and avoid clicking suspicious links, though these are weak controls against a determined attacker.

No CVE identifier has been assigned to this vulnerability at the time of disclosure. Apple has not yet released a patch or public statement addressing the issue. The timing and severity suggest this disclosure may prompt faster remediation, as i