Private Relay Leaks Your IP: What MY SMEs Must Know

Private Relay Leaks Your IP: What MY SMEs Must Know — featured image

by

Your Privacy Promise Has a Hole

You are probably reading this on a phone — maybe an iPhone you’ve enabled iCloud+ on, because Apple’s marketing promised that iCloud Private Relay would keep your IP address hidden from websites. That’s a reasonable thing to trust when your phone carries work emails, supplier chats, and tender documents. But that trust may be misplaced.

Security researchers Tommy Mysk and Talal Haj Bakry found that iCloud Private Relay can expose your real IP address to any website that uses — or simply pretends to use — passkeys. No login pop-up, no warning, nothing visible. If a site asks for a passkey, your device answers from your actual IP, as if the private relay never existed.

Here’s the thing: this isn’t a story about a distant tech giant. It’s a story about how your business location and browsing patterns can leak out while your team handles confidential work in Malaysia.

TL;DR:

  • A passkey (WebAuthn) request can reveal your real IP even when iCloud Private Relay is on.
  • Two more WebKit features leak data: DNS prefetching in iOS 26 and WebTransport in iOS 26.4.
  • If you use an iPhone for confidential business work, someone can identify your location without you noticing. Test your device today.

What This Means in Plain Language

iCloud Private Relay is a service included with paid iCloud+ plans. It is designed to hide your IP address and DNS information when you browse the web using Safari. It routes your traffic through Apple-operated proxies, so the website you visit sees a relay server instead of your device.

Notice what that sentence didn’t say: it doesn’t cover every internet connection your phone makes. It is not a VPN that masks all traffic from a device. And according to the researchers’ findings, passkeys are exactly where it falls apart.

Passkeys rely on the WebAuthn standard, which stores a private key on your device, not in the Safari browser. When a website asks for a passkey, WebKit hands the request to the operating system’s credential service. That service issues the HTTPS request itself, directly from your device — completely unaware of the proxy Safari has configured. The destination server sees your real IP address either way.

If a website asks for a passkey and your device answers, your real IP has just left your device without Safari, without Private Relay, and without a single click from you.

The leak doesn’t even need a visible prompt. A page can set its rpId to a host of its choosing and use conditional mediation, so the credential check happens with no user interface shown. An attacker who runs a website with WebAuthn can quietly collect the IP of every visiting device. In the same investigation, Mysk and Haj Bakry found that DNS prefetching (added in iOS 26) reveals your real DNS servers, while WebTransport (added in iOS 26.4) can reveal your IP address.

How This Applies to Malaysian SMEs

Imagine you own a contracting business in Johor Bahru. You commute between Malaysia and Singapore to meet clients, and your phone holds confidential pricing for both markets. You switched on iCloud+ because you expected your IP to stay hidden wherever you go. A competitor could set up a passkey-enabled website and send your staff a link — a fake invoice, a roadshow invitation, a job advert. When any of your employees open that link, the site can initiate a silent, UI-less passkey check. The site immediately reads their real IP. It doesn’t matter if Private Relay is running; the operating system bypasses it.

Then there are passkeys on legitimate services. A growing number of platforms used by Malaysian SMEs — e-invoicing portals, bank dashboards, e-wallet admin panels — now support passkey login. Every time one of those sites calls for a passkey, it receives the device’s real IP. In most cases that’s fine; these are trusted services. But it means your data protection planning has a hole you didn’t account for. Your payroll provider, your HR system, your accountant’s portal — all of them can see the actual IP no matter what Apple’s privacy features claim.

Consider the office context. Many Malaysian SMEs operate from shared offices, co-working spaces, or home offices in residential areas. If an attacker learns an employee’s real IP, they can often narrow it down to a neighbourhood or even a specific building, especially with a Malaysian telco. For a small team in a business park, that geolocation data becomes the basis for targeted social engineering: a “technical support” call claiming to be from your internet provider — suddenly sounding very convincing because it already knows exactly where the employee is sitting and which network they’re on.

One more thing: this is not an iPhone-only problem. Because the issue is baked into how WebKit works, some third-party browsers are affected too. Your employees who switched from Safari to another browser for “privacy” still use WebKit underneath. The passkey ceremony is still handed to the operating system, and the IP still leaks.

Practical Takeaways

  • Test your own device now. Mysk and Haj Bakry created a website to let you check whether Apple’s service is leaking your IP address. Run it on both personal and company phones.
  • Stop treating Private Relay as a VPN. It protects only Safari traffic that goes through Apple’s proxies. For anything else — passkey requests, DNS lookups, WebTransport connections — it does nothing.
  • Use a full-device VPN for sensitive work. If your staff access client data, banking, or confidential documents from their phones, a VPN that covers all device traffic is a more honest safety layer than Private Relay.
  • Keep iOS updated. Apple told 404 Media it is investigating the report. A patch may arrive soon; install it quickly. Until then, assume the leak exists.
  • Stop trying to fix this by switching browsers. Since WebKit and third-party browsers share the same flaw, switching browsers won’t help. Your policy must focus on what’s installed and what network your staff use, not which browser they prefer.

Leak Summary at a Glance

What leaks How it leaks Where it appears Status
Real IP address Passkey (WebAuthn) request bypasses Private Relay WebKit’s handling of passkey ceremonies Apple says investigating
Real DNS servers DNS prefetching Added in iOS 26 Not yet addressed
Real IP address WebTransport connection Added in iOS 26.4 Not yet addressed

Details in the table are drawn from the original report and Apple’s response to 404 Media.

The Bigger Picture

This story isn’t only about Apple. It shows a pattern: operating systems keep adding modern web features — passkeys, WebTransport, prefetching — and every new feature opens a gap between what marketing promises and what engineering delivers. Apple will likely patch this particular leak. But other leaks will appear, because privacy is not a single switch. It’s the entire path your data travels, and every hop is a chance for something to slip.

For a Malaysian SME, the lesson is to build layers. A privacy feature on a phone is one layer among many. Your real protection is the combination of sensible device policies, careful staff training, network-level controls, and an honest understanding of what each tool actually does.

Browsing privacy is becoming part of operating a business in Malaysia, especially as more SMEs move into e-invoicing, e-commerce, and cross-border trade. The more sensitive information your phone holds, the more you should treat every “private” feature with healthy scepticism. Ask the same question you would ask of any supplier: if this fails, what’s the backup?

The researchers found a leak. Apple is investigating. Meanwhile, your business can act — by testing your devices, closing the gap with a full-device VPN, and teaching your team that “private browsing” and “hidden IP” are not the same thing. That’s a small change, but it’s one that leaks can’t undo.

Ready to Streamline Your Operations?

Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →