A just has been filed against Apple alleging that its iCloud Private Relay feature does not protect IP addresses. The vulnerabilities of the service, which promises privacy, are being discussed.
A new legal process has been initiated after it was revealed that Apple’s iCloud Private Relay feature, offered to iCloud Plus subscribers, does not always hide users’ IP addresses. Findings shared by researchers Talal Haj Bakry and Tommy Mysk show that the feature is insufficient in protecting user information in reasonable circumstances.
This security vulnerability arises when users use a passkey to log in to a website or when sites prefer DNS prefetching and WebTransport systems to increase data loading speed. This situation leads to criticism that Apple’s feature, marketed with the promise of privacy, fails to fulfill its basic function.
Security vulnerability and the litigation process
In the lawsuit filed by Clarkson Law Firm on August 6, the plaintiff Edward Rickman states that he purchased the iCloud Plus subscription with the goal of hiding his IP address and Safari browsing history. The lawsuit alleges that Apple recreated the harm it claimed was impossible for users to experience through its own authentication service.
The application, which seeks class action status, requests a preliminary injunction to compel Apple to change its business practices. It also seeks compensation for monetary damages and reimbursement of legal fees for misleading consumers.
Apple has promoted iCloud Private Relay for years as a reliable method of protecting users from internet tracking. However, the fact that this service is only offered as part of the monthly paid iCloud Plus subscription has eroded user trust.
Tim Giordano, a partner at Clarkson Law Firm, argues that Apple’s brand promise of privacy contradicts this situation. Giordano states that users have paid for a service they believed provided privacy for years, only to be left vulnerable to tracking.
Researchers’ Criticism of Apple
The researchers who discovered the vulnerability created a website where users can check whether their IP addresses are protected. They stated that they preferred to share their findings directly with the public rather than inform Apple.
This decision stems from Apple’s lengthy security vulnerability investigation processes. Tommy Mysk says that Apple’s experience with security reward programs doesn’t inspire confidence that the problem will be solved quickly.
It is known that Apple previously had to pay a $250 million settlement due to the AI features in the iPhone 16 Pro. There has been no official statement from the company regarding this matter. It remains to be seen what steps Apple will take regarding this security vulnerability and what the users’ reactions will be. Do you think Apple’s privacy-focused services can maintain their credibility in the face of these types of vulnerabilities?