Apple's Private Relay, a privacy feature designed to mask users' IP addresses while browsing the web in Safari, has been found to have significant vulnerabilities. These issues arise from the way Apple's WebKit engine, the underlying technology for all browsers on iOS, interacts with passkeys and the operating system's credential service. As a result, users' real IP addresses can be exposed, even when they are using Private Relay. This is particularly concerning as it affects not only Private Relay but also the OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. The researchers who discovered these issues have developed a site to help users check if their IP addresses are exposed. This is the second privacy issue to impact Apple's paid-for privacy products, with the previous one being a bug in the Hide My Email feature that revealed users' real email addresses. Apple has acknowledged the issue and is investigating the report, but the researchers have expressed concern about the timeline for addressing the problem. The impact of these vulnerabilities extends beyond Apple's products, as all web browsers on iOS use WebKit, and the issues can potentially expose users' IP addresses through other means. This highlights the complexity of ensuring online privacy and the ongoing challenges in maintaining secure digital environments.