Apple is facing a new class action lawsuit alleging fraud, false advertising, and misrepresentation related to a recently disclosed vulnerability in its iCloud Private Relay feature.
According to 9to5Mac, security researchers revealed last week that iCloud Private Relay — a privacy tool meant to hide users’ real IP addresses from websites when browsing in Safari — often fails to do so. The feature routes traffic through two relays so that a user’s internet service provider sees only a connection to an Apple server, while the destination website sees only a temporary IP address generated by a third-party relay.
The flaw stems from how passkeys work. When a website supports (or even pretends to support) passkeys, the user’s device makes a web request outside the browser. That request bypasses Private Relay and can expose the real IP address. Researchers noted that simply claiming passkey support is enough to trigger the leak.
The lawsuit, filed by Clarkson Law Firm (the same firm that previously secured a $250 million settlement related to Apple Intelligence and Siri delays) claims Apple “knew, or should have known” that its marketing representations about Private Relay were “false, misleading, deceptive, and unlawful” when it sold iCloud+ subscriptions.
Tim Giordano, a partner at the firm, described the situation as “an outrageous betrayal of consumer trust,” stating that Apple built its brand on protecting user privacy and that subscribers paid a premium for protection that did not work as advertised, leaving them exposed to the tracking Apple had warned against.
iCloud Private Relay remains available to iCloud+ subscribers as a Safari privacy feature.
MacDailyNews Take: Wholly expected. Get ready for a settlement, eligible iCloud+ subscribers.
Please help support MacDailyNews — and enjoy subscriber-only articles, comments, chat, and more — by subscribing to our Substack: macdailynews.substack.com. Thank you!
Support MacDailyNews at no extra cost to you by using this link to shop at Amazon.

Like this really caused any harm – People will sue over anything..
Yes, billable hours.
So, claimants are thinking Apple’s Time Machine is really a time machine (all Wells) and Apple should have gone forward in time to have known, before the bug was discovered in the normal timeline, that the bug was there and should have fixed it.
I’m not a judge or even a lawyer, but if I were the judge over this lawsuit, I’d say, “Get out of my court with this, and I’m fining the plaintiffs lawyers $10,000 each for bringing this lunacy to my courtroom.”
No system is 100% safe. No sane person will ever expect that. This is pure gutter lawyering expecting a big payday. Apple’s legal team has been a farce since the Franklin case well over four decades ago. Apple’s legal team has not had a large, clear win since then. They’ve lost or caved time and time and time again. If I were the incoming CEO I’d fire over 90% of the legal staff and hire people that can actually do some good for Apple.
Prior to 2010, someone or someones would have been fired for this. At least one VP would be gone, maybe more.
Apple will likely lose this case and yet again end up spending an outrageous amount of money — $250 million — for an object lesson that could have cost a tiny fraction of that amount if they had just taken the time and effort to fully understand the ramifications of their software implementation prior to its public release. There are just too many hungry lawfirms ‘circling’ that are ready to pounce on any sloppy corporate workmanship or unmet promises. An aspect of immaturity is not fully comprehending the potential consequences of one’s actions. Is Craig’s team losing its grip?