Apple Faces Privacy Lawsuit Over iCloud Private Relay Failures

On August 6, a class-action lawsuit was filed against Apple by the Clarkson Law Firm, alleging that the company deceived consumers regarding the efficacy of its iCloud Private Relay service. The legal action, initiated by plaintiff Edward Rickman, claims that the service, which is marketed as a robust privacy tool for iCloud Plus subscribers, fails to consistently hide user IP addresses. Security researchers Talal Haj Bakry and Tommy Mysk identified that the privacy feature remains ineffective during specific web interactions, such as when users employ passkeys or utilize DNS prefetching and WebTransport methods. This legal development challenges Apple’s long-standing reputation as a primary guardian of consumer digital privacy.
- The Clarkson Law Firm filed a class-action lawsuit against Apple for misleading users about the security capabilities of iCloud Private Relay.
- Security researchers discovered that the service fails to mask IP addresses during specific web authentication and data loading processes.
- Plaintiffs are seeking injunctive relief to change Apple’s business practices alongside financial compensation for affected subscribers.
The lawsuit argues that Apple effectively nullifies its own privacy protections by re-exposing user identities through its internal authentication services.
Legal Challenges are Escalating for Apple
The core of the complaint centers on the disparity between Apple’s marketing materials and the actual technical performance of iCloud Private Relay. Subscribers pay for iCloud Plus with the expectation that their browsing habits and IP addresses will remain obfuscated from trackers and third-party websites. According to the court filing, Apple has misled its user base by charging for a service that fails to provide the fundamental protection it explicitly promises.

Tim Giordano, a partner at the Clarkson Law Firm, emphasized that Apple’s brand identity is deeply rooted in the promise of user privacy. He argues that the company has collected subscription fees for years while leaving users vulnerable to the very tracking mechanisms they sought to avoid. The lawsuit seeks to hold the technology giant accountable for what it describes as a deceptive business practice that compromises the safety of millions of users.
Researchers are Reporting Technical Inconsistencies
The vulnerabilities were brought to light by Talal Haj Bakry and Tommy Mysk, who have created a specialized website allowing users to verify whether their IP addresses are leaking during browsing sessions. Instead of following standard bug-reporting protocols, the researchers chose to make their findings public immediately.

The decision to bypass Apple’s formal security feedback channels stems from perceived inefficiency in the company’s internal review processes. Tommy Mysk noted that previous experiences with Apple’s security bounty programs did not instill confidence that the issue would be addressed with sufficient urgency. While Apple has previously settled high-profile privacy-related cases, such as the 250 million dollar settlement regarding iPhone 16 Pro AI features, it has not yet issued a formal response to these specific allegations.
Trust in Apple’s privacy-centric architecture is currently under intense scrutiny as the industry awaits a formal response from the company.
Given the ongoing debates surrounding data security, we invite you to share your perspective on whether paid privacy features truly offer enough transparency to justify their costs in the comments section below.
Your comment has been submitted,
it will be published after approval.