A proposed class-action lawsuit filed Thursday accuses Apple of fraud, alleging that a Private Relay problem means that iCloud+ subscriptions failed to deliver the privacy protection Apple promised.
If you ever paid for iCloud+ to gain the peace of mind Private Relay offered, the privacy shield you paid extra for had a hole in it the whole time. And Apple is now getting sued over it.
Apple faces class action over iCloud Private Relay failures
Rather than just another Apple security bug, this legal battle shows what happens when a company’s privacy promise becomes part of the product its customers pay for. iCloud+ subscribers didn’t simply buy extra storage space. Apple pitched Private Relay as a reason to hand over more money in exchange for stronger protection from online tracking.
Now, researchers say that protection could be bypassed in ways that exposed users’ real IP addresses.
The proposed class action lawsuit, filed by California man Edward Rickman, argues that Apple defrauded users by promising more privacy than it actually delivered.
“Year after year, Apple continued to promise its subscribers Private Relay capabilities, reinforcing the notion that only on Safari, with the use of Private Relay tools, Apple users can be protected,” the complaint alleges. “But in reality, Apple’s promise that Private Relay’s dual-relay design made it structurally impossible for any single party to see both a user identity and the destination of their traffic has never been true.”
A familiar law firm shows up
Rickman v. Apple Inc. comes from Clarkson Law Firm, the same outfit that sued Apple over delayed Siri AI features and secured a $250 million settlement.
The new Private Relay complaint, filed in U.S. District Court for the Northern District of California in San Jose, accuses Apple of false advertising, misrepresentation and fraud in how it marketed iCloud+ subscriptions. The lawsuit argues that Apple knew, or should have known, that its privacy claims about Private Relay weren’t holding up.
How did Private Relay expose user info?
The lawsuit follows the recently published security research about Private Relay that found the feature could be bypassed through passkey support checks. If a website supports passkeys, a device could make a request outside the browser.
This, in turn, allowed it to bypass Private Relay’s protection and expose your real IP address.
Here’s the kicker: A website doesn’t even need to actually support passkeys. Just appearing to do so could trigger the leak. That’s a rough one for a feature Apple has marketed as a near-VPN-level privacy tool for years.
Security researchers revealed the flaw last week alongside two other privacy problems involving DNS prefetching and WebTransport connections. Both of those could similarly expose user data despite the proxy being active.
Apple built its reputation on this stuff
Privacy has been at the core of Apple’s pitch for ages. It’s in the keynotes, the billboards and App Store privacy labels. Apple CEO Tim Cook even went so far as to call the company’s privacy features a “fundamental human right.”
So a lawsuit claiming Apple broke that promise cuts closer to the brand than other legal dramas.
“Year after year, Plaintiff and Class Members paid subscription fees for iCloud+ in reliance on Apple’s representations that Private Relay would hide their IP address and browsing activity in Safari,” the complaint says. “But instead, Apple delivered a system that recreates through its own credential service the precise harm Apple told the world it had made impossible. Because Private Relay did not work, subscribers received less than Apple promised and overpaid for their iCloud+ subscriptions.”
Class action lawsuits against Apple are fairly common — and not all of them stick. Apple likely will patch the Private Relay problem and other WebKit leaks in upcoming iOS and macOS updates. That would happen irrespective of where the lawsuit goes.
Apple has not yet responded to the allegations.
