Apple's iCloud Private Relay Leaks Real IP Addresses via WebKit Passkey Flaw
Security researchers Tommy Mysk and Talal Haj Bakry say three WebKit flaws can expose real IP addresses and DNS servers even with Apple’s iCloud Private Relay enabled for iCloud+ subscribers. They cite issues affecting WebAuthn passkeys, DNS prefetching, and WebTransport, with availability from iOS 18.0, iOS 26.0, and iOS 26.4. Apple’s iOS browser requirement for WebKit means other iOS browsers, including OnionBrowser, may be affected.
How this was made

The 30-second read
Why it matters
If accurate, the flaws weaken the practical privacy guarantees of iCloud Private Relay, especially since the passkey path is handled by the OS and bypasses the relay proxy.
Market read
Traders should monitor for Apple’s security response (patch timing, acknowledgements, and any changes to Private Relay behavior) because privacy trust is a recurring valuation and regulatory risk factor for Apple.
What to watch
Market impact depends on whether Apple acknowledges the issue, the severity/likelihood of exploitation in the wild, and whether any regulatory or class-action activity follows.
Background
The piece describes three WebKit-related leaks (passkey/WebAuthn, DNS prefetching, and WebTransport) that can reveal real IP/DNS despite iCloud Private Relay being enabled.
Ticker impact
Researchers say WebKit flaws can expose real IP and DNS even with iCloud Private Relay enabled, affecting Apple’s iCloud+ privacy feature on iOS.
Near-term: limited direct earnings impact, but elevated headline risk and potential regulatory or reputational overhang. Medium-term: watch for Apple security patches and any iCloud Private Relay changes.
This is a security disclosure tied to Apple’s core browser engine and iCloud Private Relay behavior. While it does not quantify financial damage, it can drive urgent patching and reputational risk, which markets often price into large-cap tech risk premia.
Market effects
Raises scrutiny on mobile privacy claims and browser-engine security across iOS ecosystems, potentially increasing competitive pressure on privacy messaging.
Primarily US-listed Apple headline risk; could spill into broader US tech sentiment around security and privacy.
Global iOS user base and privacy tooling make the issue relevant worldwide, increasing the chance of international media/regulator attention.
Counterpoint
Apple may quickly mitigate via iOS updates, limiting long-lived damage; the article describes technical pathways rather than confirmed widespread exploitation.
Key entities
- companyApple
Subject of the report, with iCloud Private Relay and WebKit/iOS credential handling implicated in the described leaks.
- researchersPsylo browser researchers (Tommy Mysk, Talal Haj Bakry)
Disclosed the WebKit flaws and provided the technical explanation for how real IP/DNS can be exposed.
- softwareOnionBrowser (Tor browser)
Mentioned as impacted because iOS browsers must use Apple’s WebKit engine.





