According to the researchers, malicious or standard websites that support passkeys—a secure login method intended to replace passwords—can bypass these protections to see a visitor's true location and network information.
This vulnerability matters because it undermines the fundamental promise of Apple’s privacy infrastructure.
While Private Relay is intended to hide browsing history from network providers and websites, the researchers found that certain web requests are handled by the device's operating system rather than the browser itself.
Because these requests bypass the encrypted proxy path, a user’s real IP address is exposed to the destination server.
This creates a concrete risk for individuals who rely on these tools to prevent websites from building profiles of their identity and location.
The leak is particularly significant for iOS users because Apple requires all mobile browsers to use its WebKit engine, meaning third-party apps cannot easily implement their own fixes.
Mike Tigas, the creator of OnionBrowser, described the situation as dire because the root cause lies entirely within Apple's software framework.
While the official Tor Browser on other platforms is unaffected, Apple has stated it is currently investigating the report.
This discovery follows a similar recent issue where Apple’s Hide My Email feature was found to be revealing actual user email addresses.