- Researchers found multiple issues that can expose a user’s real IP despite Private Relay.
- The problem is tied to passkey-related requests that bypass Safari’s Private Relay path.
- Apple has acknowledged the report and says it’s investigating.
Passkeys were supposed to fix our login headaches, but as we recently saw with Google Password Manager, transitioning to passwordless security can expose unexpected cracks in your privacy. Now, Apple is facing similar scrutiny after researchers uncovered a WebKit flaw that lets websites bypass iCloud Private Relay and expose users’ real IP addresses during passkey requests.
Discovered by security researchers Tommy Mysk and Talal Haj Bakry, the vulnerability centers on how WebAuthn requests interact with iOS (via 404 Media). When a site prompts for a passkey or even pretends to support one, the network request isn’t processed inside Safari’s standard web browser stack. Instead, Apple’s system-level credential service steps in to handle the fetch directly.