In early August 2026, Apple faced a serious legal challenge that calls into question the effectiveness of one of the key security features of its ecosystem. The law firm Clarkson filed a class-action lawsuit against the tech giant, accusing it of fraud and breach of privacy protection obligations. At the center of the conflict is the 'Private Relay' feature, which is part of the paid iCloud+ subscription and is positioned as a tool for hiding users' digital footprints.
Technical essence of the vulnerability: how the bypass works
The 'Private Relay' feature was developed to ensure privacy similar to a VPN, but with a more refined architecture. In normal mode, it splits the connection into two stages: the provider and Apple's first relay see the user's real IP address but do not know the destination; the second relay (a third-party partner) knows the destination address but does not know the client's IP address. Cybersecurity researchers discovered a critical flaw in this scheme related to Access Tokens technology.
The vulnerability lies in the fact that the user's device sends web requests outside the browser context. If the website the user visits supports access tokens (or even just simulates support for them), it can intercept these requests and reveal the user's real IP address. This happens unnoticed by the user, who believes their traffic is securely encrypted and hidden.
Accusations of fraud and betrayal of trust
The law firm Clarkson, which initiated the lawsuit, has previously succeeded in court against Apple, winning $250 million for delays in updating Siri's artificial intelligence features. This time, the argumentation is based on a fundamental breach of trust. In their statement, lawyers noted that Apple built its global brand on the promise of protecting privacy, and no other company markets this as aggressively.
According to the plaintiffs, users have paid for a feature for years that effectively did not work as advertised, exposing them to tracking, profiling, and targeted advertising. Clarkson calls this an 'outrageous violation and betrayal of consumer trust and the law.' The lawsuit qualifies Apple's actions as fraud, as the company continued to sell the iCloud+ subscription while knowing or ignoring potential risks.
Lack of reaction and context of the incident
At the time of publication (August 12, 2026), no official comment had been received from Apple representatives. The company traditionally waits before making public statements on security issues, but in this case, silence could be perceived as a lack of a quick plan to fix the situation. The 'Private Relay' incident serves as another reminder that even in 2026, data privacy issues remain one of the most vulnerable points in the digital ecosystem, despite claims of 'privacy by default'.