In the quiet architecture of digital trust, Apple now faces a reckoning: the privacy promise embedded in iCloud Private Relay—a feature millions pay for to shield their browsing from surveillance—has been found to leak the very information it was designed to conceal. Researchers discovered in early August 2026 that websites can still identify users' real IP addresses despite the feature being active, and Clarkson Law Firm filed a class action on August 11th alleging fraud and false advertising. The case touches something older than any software flaw—the question of what we owe one another when
Apple faces class action over Private Relay privacy flaw affecting millions
Websites can still see your real IP address even when Private Relay is switched on
Why does this matter if Private Relay was never a full VPN anyway? Wasn't it always limited?
The limitation was always there—it only covered Safari. But the promise was that within that scope, it actually worked. You paid for it specifically to hide your IP from websites. If websites can see your real IP anyway, the whole product is broken.
How many people are we talking about?
Millions. Everyone with an iCloud+ subscription has Private Relay enabled by default. That's a huge installed base, and most of them probably didn't know about the flaw until the researchers published their findings.
Can Apple just patch this and move on?
Technically, yes. But the lawsuit isn't really about whether a patch is possible—it's about whether Apple misled people about what they were buying. That's a different question. Even if Apple fixes it tomorrow, the company still sold a broken product under false pretenses.
Why does the WebKit requirement make this worse?
Because it means the vulnerability isn't just a Safari problem. Every browser on iPhone and iPad has to use Apple's engine, so the bypass works everywhere. That's a much larger attack surface than most people realized.
What should someone do right now if they care about privacy?
If you need real IP hiding, you need a proper VPN that works at the system level. Private Relay can't be trusted for that anymore. It's a hard lesson in not assuming a feature works just because a company says it does.
O Pulso
- Researchers Tommy Mysk and Talal Haj Bakry published findings on August 4th showing that multiple bypass methods allow websites to see users' real IP addresses even with Private Relay enabled—unraveling the core promise of the feature.
- Because Apple mandates the WebKit engine for every browser on iPhones and iPads, the vulnerability extends far beyond Safari, catching even privacy-focused browsers like Tor's OnionBrowser in the same trap.
- The researchers released a public checker tool, turning an abstract security flaw into something millions of iCloud+ subscribers could personally verify—and many did, discovering their protection was illusory.
- Clarkson Law Firm, fresh from a $250 million settlement against Apple over delayed AI features, filed a class action on August 11th alleging Apple knowingly or recklessly sold a privacy feature that didn't function as advertised.
- Apple has issued no public statement, released no patch, and set no timeline for a fix—leaving iCloud+ subscribers in a state of unresolved exposure with little recourse beyond switching to a full-system VPN.
In the quiet architecture of digital trust, Apple now faces a reckoning: the privacy promise embedded in iCloud Private Relay—a feature millions pay for to shield their browsing from surveillance—has been found to leak the very information it was designed to conceal. Researchers discovered in early August 2026 that websites can still identify users' real IP addresses despite the feature being active, and Clarkson Law Firm filed a class action on August 11th alleging fraud and false advertising. The case touches something older than any software flaw—the question of what we owe one another when we sell the idea of safety.
On August 11th, 2026, Clarkson Law Firm filed a class action lawsuit against Apple, alleging that iCloud Private Relay—a privacy feature bundled into iCloud+ subscriptions—fails to deliver on its central promise. The suit follows a security disclosure published one week earlier by researchers Tommy Mysk and Talal Haj Bakry, who identified multiple methods by which websites can bypass Private Relay and retrieve users' real IP addresses, the very data the feature was designed to obscure.
Private Relay was marketed as a browsing shield: it routes Safari traffic through two Apple-controlled relays, giving websites a temporary IP address rather than the user's actual one. Apple positioned it as protection against location tracking and behavioral profiling by advertisers and data brokers. It was never a full VPN—it only covered Safari—but within that scope, it was supposed to be dependable.
What made the researchers' findings especially significant was their breadth. Apple requires all browsers on iPhones and iPads to run on its WebKit engine, meaning the bypass techniques work across every browser on those devices, not just Safari. Even privacy-focused alternatives like Tor's OnionBrowser are affected. To make the vulnerability tangible, the researchers built a checker tool that let users test their own connections in real time—transforming a technical disclosure into a personal reckoning for millions of subscribers.
Clarkson Law Firm brings relevant momentum to the case: earlier in 2026, the same firm secured a $250 million settlement from Apple over the delayed rollout of Apple Intelligence and Siri features. The current lawsuit rests on claims of fraud and false advertising, arguing Apple sold a privacy product that didn't work as described.
Apple has not responded publicly, announced a patch, or offered a timeline for remediation. Private Relay remains available and active. For users concerned about location privacy, security experts point toward full-system VPNs as the more reliable alternative—though they come with their own costs and trade-offs. For now, the people who paid for privacy have been left to reckon with the possibility that they never had it.
On August 11th, Clarkson Law Firm filed a class action lawsuit against Apple, alleging that iCloud Private Relay—a privacy feature millions of people pay for as part of their iCloud+ subscriptions—doesn't actually do what the company promised. The suit centers on a fundamental failure: websites can still see your real IP address even when Private Relay is switched on, defeating the entire purpose of the feature.
Private Relay is supposed to work like a privacy shield for Safari browsing. When enabled, it routes your traffic through two separate Apple-controlled relays, creating a buffer between you and the websites you visit. Your internet provider sees only that you're connected to an Apple server. The websites themselves receive a temporary, rotating IP address instead of your actual one. Apple marketed this as protection against location tracking and behavioral profiling by advertisers and data brokers. It's not a full VPN—it only covers Safari traffic, not all device activity—but for the specific use case of web browsing, it was meant to be reliable.
The lawsuit was triggered by a security disclosure published on August 4th by researchers Tommy Mysk and Talal Haj Bakry, who discovered multiple methods by which websites could circumvent Private Relay and obtain users' real IP addresses. What made their findings particularly damaging was the scope: the vulnerability isn't limited to Safari. Because Apple requires every browser on iPhones and iPads—including privacy-focused alternatives like Tor's OnionBrowser—to use Apple's WebKit engine under the hood, the same bypass techniques work across all of them. This means the flaw affects far more users than those relying solely on Safari.
The researchers even built a checker tool that allows users to test whether their own connection is currently leaking their real IP address. The tool became a way for millions of iCloud+ subscribers to verify whether they were actually getting the protection they were paying for.
Clarkson Law Firm is no stranger to taking on Apple. The same firm won a $250 million settlement from the company earlier in 2026 over allegations that Apple delayed the rollout of Apple Intelligence and Siri features. That track record may have emboldened them to pursue this case, which hinges on claims of fraud and false advertising—arguing that Apple knowingly or recklessly sold a privacy feature that didn't work as advertised.
Apple has not issued any public statement about the lawsuit or the underlying vulnerability. Private Relay remains active and available to all iCloud+ subscribers. The company has not announced a patch or timeline for fixing the flaw. For users who are part of the class action, there's nothing to do at this stage; membership is automatic if you hold or held an iCloud+ subscription during the relevant period.
The practical implication is clear: if location privacy from websites is a genuine concern, iCloud Private Relay is no longer a reliable tool. A full-system VPN, which encrypts all device traffic at the operating system level rather than just Safari browsing, would sidestep this particular vulnerability. But that requires a separate subscription and introduces its own trade-offs. For now, millions of people who believed they had paid for privacy protection have learned they didn't have it at all.
Citações Notáveis
Private Relay is supposed to hide details like your location from websites you visit by routing traffic through two separate relays, but researchers found multiple ways websites could still see users' real IP addresses.— Clarkson Law Firm lawsuit allegations