- A law firm sued Apple, saying its Private Relay tool did not protect user privacy as promised.
- Experts found bugs that can reveal a user’s real IP address, even with Private Relay turned on.
- Apple has not responded yet, but the same law firm won a $250 million case against Apple before.
Apple now faces a big lawsuit. It comes from Clarkson Law Firm, and it involves iCloud Private Relay. The suit claims Apple lied about how well this privacy tool works. It also claims Apple broke false advertising rules and cheated iCloud+ customers out of their money.
According to The New York Post, security experts found several bugs in Private Relay. These bugs can expose a user’s true IP address. They can also leak DNS information. This can happen even when someone turns Private Relay on. The lawsuit claims Apple knew about these issues, or should have known, before it sold iCloud+ plans to customers.
How Private Relay Works, and Where it Breaks
Private Relay is a feature built for Safari. It hides two things from view: a user’s identity, and the websites that user visits. Apple runs the first relay point. A different company runs the second one. Neither company alone can see the whole picture. This setup should stop anyone from tracking a person’s full browsing history.
But researchers found a serious flaw tied to passkeys. A website can send a passkey request that skips Safari entirely. The device handles this request on its own, and Private Relay’s protection never gets involved.
Because of this, a website can grab a person’s real IP address. Sometimes, this happens without even showing a passkey prompt. It can happen even on a site that just claims to support passkeys, whether it truly does or not.
Researchers also found two more problems. One centers on DNS prefetching. The other involves WebTransport, a newer feature Apple added with iOS 26. Both of these can expose a user’s real IP address or DNS servers under certain conditions. Since Apple requires every iOS browser to run on WebKit, this problem isn’t limited to Safari. Any browser on an iPhone could carry the same risk.
What the Lawsuit Says About Apple
Clarkson Law Firm represents the people suing Apple. A partner at the firm, Tim Giordano, spoke about the case. He said Apple sold a privacy feature that failed to protect the people who paid for it. According to Giordano, Apple’s brand has always rested on strong privacy promises.
He argued that customers paid extra money for iCloud+, expecting real protection in return. Instead, he said, that protection did not hold up, and it left users open to the very tracking and profiling that Apple claimed to guard against. He called this outcome a serious breach of trust, and a violation of the law.
This isn’t the first time Clarkson has taken Apple to court. The firm previously sued Apple over delays to personalized Siri features. That case ended with a massive result. Apple agreed to pay $250 million to settle it. The deal came together in December 2025.
What Happens Next
Right now, this new Private Relay case is still a proposed class action. That means a court has not yet approved it to move forward as a full class lawsuit. Apple has not given any public response so far.
Tech companies face growing legal scrutiny over privacy claims. Texas recently sued Meta and WhatsApp, alleging that WhatsApp’s end-to-end encryption promises were misleading because the company allegedly had access to user communications It remains unclear how the company plans to answer these claims, or how long the case might take to resolve.
For everyday iCloud+ subscribers, the case raises real questions. Many people pay for iCloud+ specifically because of privacy tools like Private Relay. If the claims in this lawsuit hold up, it could affect how much people trust that feature going forward. It could also affect how other tech companies market their own privacy tools in the future.
For now, nothing changes for current iCloud+ users. Private Relay still works the same way it did before this lawsuit began. Anyone worried about the reported bugs can watch for updates from Apple or follow how the lawsuit moves through the courts in the months ahead.
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
Suspected Chinese Hackers Exploit Critical VMware vCenter Flaw Across 47 Countries
Several servers across 47 countries record a compromise via an exploit of Vmware vCenter directory-t...
WhatsApp Tests On-Device Scam Alert without Reading User Messages
WhatsApp is testing a new tool called Scam Alert that spots scam messages right on your phone. The t...
Hackers Exploit TrueConf Servers to Distribute Malware Through Fake Software Updates
A hacker group named Head Mare broke into TrueConf video meeting servers and swapped safe installers...
New NatJack Attack Exposes Hidden Weakness in How Networks Handle Internet Connections
Security researcher Malcolm Stagg has uncovered NatJack, a new class of attacks that exploits a fund...
Germany Warns Companies Over Missing Security Contact Files on Most Websites
Germany’s cyber agency BSI wants every website to publish a security.txt file so researchers c...
TP-Link Patches 15 Omada Flaws that could Let Hackers Compromise Entire Networks
TP-Link fixed a total of 15 vulnerabilities in the ZTP solution that powers its Omada networking eco...