A significant privacy vulnerability has emerged in Apple's vaunted security infrastructure, potentially undermining one of its premium privacy offerings. Security researchers have discovered that flaws within WebKit, the mandatory browser engine for all iOS applications, can inadvertently expose user IP addresses to the internet—even for those paying for Apple's iCloud+ Private Relay subscription service, which was specifically designed to prevent such exposure.

The vulnerability was brought to light in early August when cybersecurity researchers Talal Haj Bakry and Tommy Mysk identified three distinct defects within WebKit that create pathways for data leakage. Their investigation began when users of Psylo, a privacy-focused browser the duo developed, reported suspicious DNS leaks on certain websites. What followed was a deeper examination that uncovered not only DNS vulnerabilities but also direct exposure of device IP addresses—the unique numerical identifiers that essentially serve as digital home addresses for internet-connected devices. Because Apple's App Store policies mandate that every third-party iOS browser must rely on WebKit, the vulnerability affects a broad ecosystem of applications, including all iOS-based Tor browsers and other privacy-oriented tools.

The situation presents an ironic contradiction at the heart of Apple's privacy strategy. Private Relay, introduced in 2021 as an iCloud+ premium feature, employs a sophisticated two-relay system designed to ensure that no single party—not even Apple itself—can simultaneously see both a user's identity and their browsing destinations. The feature has been central to Apple's marketing of iOS as a privacy-centric platform, distinguishing it from competitors. Yet the flaw emerges precisely when users employ passkeys, which Apple itself has promoted as a more secure authentication method compared to traditional passwords. Because passkeys require devices to make authentication requests outside the normal browser process, these requests bypass the Private Relay protection entirely, leaving IP addresses exposed during what should be protected transactions.

Understanding the significance of IP address exposure requires appreciating what this data reveals. Internet Protocol addresses function as precise digital identifiers that enable both legitimate network communication and invasive tracking. These numerical addresses can pinpoint user locations down to specific postal codes, providing internet service providers, website operators, and malicious actors with granular geographic information. Beyond location revelation, exposed IP addresses create vulnerability windows for certain cyberattacks and enable persistent tracking of browsing behaviour across multiple sessions and devices. For users in regions with restrictive internet policies or those seeking to maintain anonymous browsing, IP address leakage represents a serious breach of security assumptions.

The WebKit vulnerabilities highlight a structural challenge within Apple's ecosystem. The company's requirement that all iOS browsers use a single rendering engine creates a single point of failure—when security issues exist in WebKit, they potentially affect every browser application available on iOS. This contrasts sharply with Android, where multiple browser engines can operate. Researchers noted that the Tor Project and Onion Browser developers were notified of the findings, and Psylo itself was updated to implement protective measures. However, the underlying WebKit flaws persist across Safari and other iOS browsers unless Apple addresses them at the engine level.

Apple's privacy positioning has become increasingly central to its brand identity and competitive differentiation. The company has invested heavily in privacy-focused advertising campaigns, including prominent marketing in June that positioned Safari as superior to Chrome in privacy protection. This commitment traces back to 2017, when Apple introduced Intelligent Tracking Prevention, a feature designed to restrict trackers' ability to harvest user location data through IP address collection. The Private Relay feature was meant to build upon this foundation, offering subscribers an additional security layer. The distinction between Private Relay and Safari's Private Browsing mode is worth noting: while the latter provides enhanced privacy protections and prevents browsing history retention within individual tabs, only Private Relay actually shields IP addresses and browsing activity from external monitoring.

For Malaysian and Southeast Asian users, the implications extend beyond individual privacy concerns. The region has seen growing awareness of data privacy issues, reflected in regulations like Malaysia's Personal Data Protection Act and similar frameworks across ASEAN nations. Users in the region who have invested in iCloud+ subscriptions specifically for the Private Relay feature's privacy guarantees have been operating under false security assumptions. Furthermore, journalists, activists, and others in the region who rely on privacy tools for legitimate protection face unexpected vulnerabilities precisely in the tools they trust most.

The disclosure also raises questions about Apple's vulnerability disclosure and remediation processes. Despite flagging the issue on August 5, Apple has not publicly responded to inquiries about timelines for fixes or acknowledgement of the specific vulnerabilities. This silence from one of the world's largest technology companies stands in contrast to the transparent communication users have come to expect around security matters. The longer these WebKit flaws remain unpatched, the more users unknowingly operate under a false sense of security.

Looking forward, this incident suggests that premium privacy features require continuous security auditing and transparency, not merely marketing claims. Users should reassess their security assumptions and consider whether paid privacy services are delivering their promised protections. For Apple, the challenge involves balancing its unified ecosystem architecture with security requirements that may necessitate more permissive approaches to browser diversity on iOS. Until WebKit's vulnerabilities are comprehensively addressed, users seeking genuine IP address protection may need to explore alternative approaches or platforms that offer more distributed security models.