Apple’s Private Relay Feature Found to Leak User IP Addresses

A significant flaw has been identified within Apple’s Private Relay feature, which theoretically aims to mask users’ IP addresses from websites they visit. This bug allows for the potential exposure of users’ real IP addresses, compromising the intended privacy protection.

Understanding the Private Relay Vulnerability

The Private Relay function is designed to enhance user privacy on Safari by obscuring their IP addresses. It achieves this by routing internet traffic through a secure, multi-hop encrypted network, making it difficult for websites to track users. However, a specific implementation bug in Apple’s system can bypass this mechanism, leading to the unintended revelation of the user’s true IP address.

Implications for User Privacy

The exposure of real IP addresses directly contradicts the core purpose of Apple’s Private Relay, potentially undermining the privacy of users who rely on this feature for anonymity. This vulnerability means that websites and online services could still identify a user’s location and potentially their identity, even when Private Relay is actively enabled.