Apple has quietly addressed a vulnerability in iCloud Private Relay that could expose a user鈥檚 IP address even when the privacy feature was enabled, according to a developer who tracked the fix. The patch appears to have arrived in the iOS 26.6.1 update, along with matching releases for Apple鈥檚 other operating systems, though Apple did not mention the security fix in its release notes. The issue affects U.S. users who pay for iCloud Plus, which includes Private Relay, a service that routes Safari and WebKit-based app traffic through proxy servers to mask the user鈥檚 location and browsing data. It is not a full VPN, as it does not hide all internet traffic.
The flaw was first reported in August by developers Talal Haj Bakry and Tommy Mysk, who found that devices with Private Relay enabled could still leak IP addresses in three specific scenarios. The pair set up a test page at leaks.psylo.app where users could check if their device was vulnerable. On Tuesday, Mysk posted on social media that Apple鈥檚 latest operating system updates, including iOS 26.6.1, resolved the problem, and that the test page now correctly shows a masked IP address instead of the real one when Private Relay is turned on in the iCloud settings.
Mysk also said in a follow-up post that it was nearly impossible for Apple to have fixed the issue so quickly if the researchers had reported it to the company first, suggesting the public disclosure prompted the response. He noted that the fix appears to apply only to Safari, not to other potential vectors. Apple did not immediately respond to a request for comment on the patch or its omission from the security notes.
The vulnerability has already sparked legal action in the United States. Clarkson Law Firm, which previously negotiated a $250 million settlement with Apple over how the company advertised its Apple Intelligence features at launch, filed a lawsuit over the Private Relay issue. The same firm has also recently sued smart ring maker Oura. A representative for Clarkson did not immediately respond to a request for comment.
For U.S. consumers, the fix means that iCloud Private Relay subscribers who have updated their devices can once again expect their real IP addresses to stay hidden when browsing in Safari. The feature remains a paid add-on, separate from standard VPN services, and requires users to enable it manually under iCloud settings. Apple鈥檚 silence in its official release notes leaves some ambiguity about the scope of the patch, but the public test page indicates the leak is closed for those running the latest software.
More cybersecurity news from TechManNews.







