A privacy feature that Apple markets as a shield for your browsing identity has a crack in it. Security researchers have demonstrated that Safari's Private Relay, an opt-in tool for iCloud+ subscribers, can be tricked into revealing a user's true IP address. The discovery undermines the trust placed in a feature designed specifically to keep that information hidden. The findings were published in a blog post on Tuesday by researchers Talal Haj Bakry and Tommy Mysk, who also launched a public website that lets anyone test whether their real IP address is exposed. TechCrunch ran the test and confirmed the leak, watching its own true IP address surface despite Private Relay being active. Main Developments Three separate flaws in WebKit, Apple's browser engine that powers every browser on iOS, are at the root of the problem. Each one offers a distinct path for a website to bypass the IP-masking layer that Private Relay is supposed to provide. Read also: AI Search Boosts Shopify Sales, Complements Traditional Google Mysk and Bakry deliberately chose not to report the vulnerabilities to Apple before going public. In a post on X, Mysk explained that past interactions with the company led them to expect months of delays, inconsistent communication, and even outright denial of the issue's severity. Apple has not yet responded to requests for comment on the researchers' findings. The company's silence leaves users without an official timeline for a fix or even confirmation that the flaws exist. Background Private Relay is not a VPN, a distinction that matters for understanding its limits. While a VPN encrypts and routes all of a device's traffic at the system level, Private Relay only functions within Safari and is available exclusively to paying iCloud+ customers. The feature works by sending web traffic through two separate servers, each of which holds only part of the information needed to identify the user. This design is meant to ensure that no single relay can see both who you are and which sites you visit. Mysk is no stranger to building privacy tools. The researchers' own browser, called Psylo, has already been updated with mitigations that prevent the same IP-leaking tricks from working, according to their statements. Why It Matters For users who rely on Private Relay to keep their browsing location secret, this vulnerability turns a privacy feature into a false sense of security. Anyone visiting a malicious site could potentially unmask their true IP address without their knowledge. The decision to bypass responsible disclosure also raises broader questions about how Apple handles security research. If researchers feel their reports are ignored or downplayed, they may be more inclined to publish findings directly, leaving users exposed in the meantime. Websites can already fingerprint browsers in countless ways, but an IP address remains one of the most direct identifiers available. A leak of this magnitude undermines the entire purpose of the feature for those who opted in. What's Next Apple now faces pressure to acknowledge the flaws and issue a patch for WebKit. Until then, any iCloud+ subscriber using Safari remains potentially exposed, and the researchers' public test site gives anyone a way to check their own status. The situation also leaves open questions about whether Apple will revise its approach to handling vulnerability reports. For now, users who want stronger protection may need to look beyond Private Relay — perhaps at a dedicated VPN or a browser like Psylo that already claims to close this gap.