iCloud Private Relay, a security feature offered by Apple, has been found to have a critical problem by a pair of security researchers. Even when using Safari, a website can easily obtain a user's real IP address.
The issue was discovered by researchers Talal Haj Bakry and Tommy Mysk, who have already informed Apple about the problem. According to their report, Apple acknowledged the issue as "dire" but did not provide a timeline for addressing it.
iCloud Private Relay is not a traditional VPN, but rather a feature that operates within the Safari browser. It does not protect requests made outside the browser, such as those made for Passkey credentials. This is because Passkeys use the WebAuthn framework on Apple devices, which operates outside the browser.
The issue also affects browsers that use WebKit's proxy relay, including some Tor browsers. To check if you are affected, a proof-of-concept site can be used.
Apple's decision to allow the researchers to disclose the issue before a fix suggests that the company wants users to be aware of the problem. However, the fact that it may require a software update on devices and not just a back-end server fix may mean that it takes some time to address.
iCloud Private Relay operates in a different way than a traditional VPN, which routes all internet traffic through other servers. This difference is the root cause of the new issue, which can be exploited by websites to obtain a user's real IP address.
Apple will need to address this issue quickly, especially considering the recent vulnerability in Hide My Email that exposed real email addresses. Although the issue with Hide My Email was fixed quickly, it only required a back-end server fix, whereas this issue may require a software update.