Apple Privacy Leak: Why Your SME’s Data Is at Risk

Apple Privacy Leak: Why Your SME's Data Is at Risk — featured image

by

The invisible barrier that isn’t

You bought iCloud+ because Apple promised that your real IP address would be hidden while you use Safari. For a Malaysian SME owner, that promise feels important—you handle client contracts, banking logins, supplier negotiations and employee payslips from your phone every day. Now, security researchers have discovered that iCloud Private Relay is leaking real IP addresses to websites that use or pretend to use passkeys. The feature designed to mask your location can quietly hand over your true IP without any prompt or indication.

Tommy Mysk and Talal Haj Bakry, the researchers behind the finding, created a test page that allows you to see whether Apple’s service exposes your IP address. As reported by MacRumors, the problem isn’t a minor glitch—it’s baked into how WebKit, the engine behind Safari, handles passkeys and other authentication processes. If you’re one of the millions of Malaysians who use an iPhone as your primary business device, this matters to you directly.

What happened

iCloud Private Relay is a paid service that sits between Safari and the websites you visit, encrypting traffic in two separate hops so your IP address is hidden from both the site and your network provider. But Private Relay only protects traffic that goes through Safari’s normal browsing path. The flaw exists in a separate flow: WebAuthn, the standard behind passkeys. When a website requests a passkey, the browser hands the request to the operating system’s credential service, and that service issues an HTTPS request directly from your device, completely bypassing Private Relay’s proxy. The destination server sees your real IP address.

Worse, an attacker doesn’t need to present a visible passkey prompt to trigger this leak. The researchers found that a page can set rpId to a host of its choosing, and the fetch fires even without user interaction using conditional mediation form that never displays a password field. That means a malicious website you simply open can silently send your IP address to the attacker’s server without you ever noticing. The team also discovered two other WebKit features leaking data: DNS prefetching, added in iOS 26, exposes your real DNS servers, and WebTransport, added in iOS 26.4, can reveal your IP address.

Because the fetch is issued by the operating system’s credential service rather than by Safari, it never enters Private Relay’s proxied path. The destination server sees the device’s real IP address either way.

The researchers also warned that because the issue lives in WebKit, some third-party browsers are affected too. Apple has told 404 Media that it is investigating the report, but until a fix is released, you’re exposed. You can test your own device using the researchers’ website, and the team suggests using a VPN for more protection in the meantime.

Why this matters for Malaysian SMEs

Let’s be honest about how you work. You check emails on your phone, transfer money through banking apps, access your company’s accounting dashboard from a coffee shop in Bangsar, and send contracts to clients in Singapore or China using Safari. You may have paid for iCloud+ specifically to keep your browsing private, especially when using public Wi-Fi at airports or co-working spaces. But this leak means your real IP address—and therefore your approximate location and office network footprint—can be captured without you ever knowing. For a small business owner, an exposed IP can be the starting point for targeted phishing attacks, supplier fraud, or attempts to break into your corporate accounts.

There’s also the data protection dimension. Malaysia’s Personal Data Protection Act 2010 requires you to take reasonable steps to protect personal data you process. If you have a team of employees using company iPhones to handle customer information, a silent IP leak on every device is a compliance headache waiting to happen. You can’t control Apple’s code, but you can take steps to reduce your exposure. Start by checking whether your own device leaks. Then consider using a dedicated VPN for all business-related browsing, even on Safari. Remember, Private Relay is not a VPN—it only works on certain traffic, and now we know it doesn’t even do that reliably.

Another reason this matters is the passkey shift. Apple has been pushing passkeys as the future of authentication, and many Malaysian businesses are adopting them for staff access to cloud tools. This discovery doesn’t make passkeys useless—but it does mean you shouldn’t assume your privacy features are protecting you during authentication processes. If you manage your IT, you can configure your company to use a password manager with its own encrypted browser, or activate a VPN at the router level so all devices are covered. For a small team, a simple policy that separates business browsing from personal browsing is surprisingly effective.

The bigger picture

This leak is not an isolated bug. It’s a symptom of the complexity that comes with modern web standards, where different components of the operating system communicate outside the browser’s protected tunnel. Every year, more features get added to WebKit, and every year, researchers find new gaps. The lesson for Malaysian SMEs is layered security. Don’t put all your trust in one vendor’s promise, even if that vendor is Apple. Your business is defined by how you protect your customers’ data and your own operational secrets. That requires layers: a VPN for remote browsing, endpoint security on all devices, regular audits of what your employees access, and a clear incident response plan.

Cloud-based automation tools are your friend in this scenario, because they centralise access control and monitoring. If you’re using a customer relationship management system or an invoicing platform in the cloud, make sure it supports single sign-on and logs all access attempts. That way, even if someone discovers your IP address, you’ll see the attack attempt early. Talk to your team about this leak tonight, not next week. Send them the test site, ask them to run it on their devices, and switch on a reputable VPN for all outbound traffic.

Leak vector What it exposes
WebAuthn certificate fetch Your real IP address, triggered silently by any site using passkeys
DNS prefetching Your real DNS servers, revealing your ISP and network details
WebTransport Your IP address, even when Private Relay is enabled

The other important thing you can do is keep your devices updated. Apple is likely to roll out a fix in a future iOS update, and when that happens, you want to be first in line. But don’t wait for that fix. Take action now: use a VPN, test your phone at the researchers’ site, and plan your security around the fact that built-in features can fail without warning. Your SME’s reputation in Malaysia is built on trust. A silent IP leak is a reminder that trust, for a digital business, starts with what’s happening inside your own device.

Ready to Streamline Your Operations?

Technology moves fast. Your operations should keep up. AutoRunBiz builds AI systems that run your daily workflows — from WhatsApp order capture to accounting. Book a free 15-min ops audit →