Apple’s iCloud Private Relay has returned to full working order following a fix in iOS 26.6.1 that patched a vulnerability capable of exposing a user’s IP address even while the feature was switched on.
iCloud Private Relay is a paid feature available only to those with an iCloud Plus subscription. When active, it routes web traffic through proxy servers to mask a user’s physical location and browsing activity. The feature is specific to Apple’s Safari web browser and apps built on Apple’s WebKit framework, and it differs from a VPN, which conceals all internet traffic across a device.
How the IP address leak was discovered
Earlier in August, developers Talal Haj Bakry and Tommy Mysk identified that Apple devices with iCloud Private Relay enabled could still leak their IP addresses in three separate circumstances. The developers set up a web page at leaks.psylo.app where users could check whether their device was affected.
Mysk later stated that the fix appeared in Apple’s iOS 26.2.1 release, alongside the corresponding 26.2.1 updates for Apple’s other operating systems, despite the change not being listed in Apple’s security release notes. Visiting the leak checker page now reports the masked IP address rather than the device’s actual address, provided iCloud Private Relay is enabled under Settings, then iCloud.
Mysk also noted that the issue was addressed unusually quickly and that the fix applied only to Safari. An Apple representative did not immediately respond to a request for comment.
Legal action follows the disclosure
Shortly after the vulnerability was revealed, it prompted a lawsuit filed by the Clarkson Law Firm, the same firm that negotiated a £197 million settlement with Apple over how the company advertised its Apple Intelligence features at launch. The firm has also recently taken legal action against smart ring maker Oura.
A Clarkson Law Firm representative did not immediately respond to a request for comment.