A class action lawsuit accusing Apple of fraud, misrepresentation, and false advertising over iCloud Private Relay was filed August 11 by Clarkson Law Firm, six days after security researchers publicly disclosed that the privacy feature leaks users’ real IP addresses in several scenarios. The suit targets iCloud+ subscribers who paid for Private Relay specifically because Apple marketed it as a tool that prevents websites from tracking them by IP.
Security researchers Tommy Mysk and Talal Haj Bakry detailed the vulnerability on August 5, identifying three distinct ways Private Relay can expose a user’s real IP address or DNS servers. The most significant involves passkeys: when a device makes a web request for passkey authentication outside the browser, that request bypasses Private Relay entirely and sends the real IP address to the destination server. Critically, the website does not need to actually support passkeys to trigger this leak; simply pretending to support them is enough. Two additional issues tied to DNS prefetching and the WebTransport protocol introduced in iOS 26 can also expose real IP addresses or DNS servers under certain conditions.
Because Apple requires all browsers on iOS to use its WebKit engine, the vulnerabilities are not limited to Safari users. The Tor browser’s iOS implementation, OnionBrowser, is affected, which prompted the Tor Project to describe the situation as “dire.” The Tor Project did not provide a timeline for addressing it on their end. Apple has said a fix is planned for Fall 2026, meaning users who depend on Private Relay for meaningful privacy protection remain exposed for at least several more weeks.
The lawsuit alleges Apple “knew, or should have known, that the Challenged Representations were false, misleading, deceptive, and unlawful, at the time that Defendant manufactured, marketed, advertised, labeled, and sold the [iCloud+] Subscriptions.” This is a standard framing for consumer fraud claims, but Clarkson has demonstrated it can close these cases: the firm previously won a $250 million settlement against Apple over its delayed Siri AI rollout, with that settlement reached in December 2025 and terms publicized in May 2026.
This is the second iCloud+ privacy feature to fail visibly in 2026. A separate vulnerability in Hide My Email allowed anyone to access a subscriber’s real email address and was fixed alongside 87 other security issues in July 2026. Two failures in consecutive months is an uncomfortable pattern for a company whose marketing has leaned heavily on privacy as a core differentiator.
Apple has not offered a specific timeline beyond “Fall 2026” for the Private Relay fix, so the gap between disclosure and patch could easily stretch two to three months. Clarkson’s track record with Apple litigation means the lawsuit carries more weight than a typical class action filing, and the next iOS security release will be closely watched to see whether a partial fix arrives sooner.
via 9to5Mac