Apple faces proposed class action accusing it of fraud and false advertising over security flaw in iCloud Private Relay, according to 9to5Mac.
The complaint was filed by law firm Clarkson, which accuses Apple of misleading iCloud+ subscribers with its marketing of Private Relay, the feature intended to protect a user’s IP address and DNS records when browsing in Safari. The company alleges that Apple knew, or should have known, that its privacy statements regarding this feature were false and misleading at the time it sold the subscriptions.
Clarkson previously sued Apple over the delay in rolling out Siri’s custom features, a case that resulted in a $250 million settlement. This deal was concluded in December 2025, although payment terms were not made public until May.
Clarkson partner Tim Giordano said Apple had built its reputation on privacy promises and argued that iCloud+ subscribers were paying extra for protection that had failed to deliver, calling it an “outrageous violation and betrayal of consumer trust and law.”
The lawsuit highlights a set of problems with WebKit that security researchers detailed earlier this month. The most serious links to password logins: A site can trigger a password check that is handled by the device’s operating system rather than Safari, bypassing Private Relay’s proxy servers entirely, sometimes without displaying any password prompts at all, even on a site that only claims to support them.
Two other issues, related to DNS prefetching and the WebTransport protocol added in iOS 26, can also expose a user’s real IP address or DNS servers under certain conditions. Since WebKit powers all browsers on iOS, the exposure isn’t limited to Safari.
