Report: Apple’s Private Relay may not be as private as thought ↦
A story by 404 Media’s Joseph Cox, who last month broke the news about a flaw in Apple’s Hide My Email feature, is now back to report that iCloud Private Relay, a feature that is supposed to obfuscate users’ IP addresses, may not be so private: A series of issues in Apple’s web browser engine — the tech underlying all browsers on iOS — means that Apple’s iCloud Private Relay tool, which is…
A recent report from 404 Media's Joseph Cox reveals that Apple's iCloud Private Relay, designed to mask users' IP addresses, may not be as private as initially advertised. The flaw stems from issues in Apple's web browser engine, which is central to all iOS browsers. These issues allow malicious attackers to potentially uncover a Private Relay user's real IP address.
Furthermore, many websites may have already collected this sensitive information inadvertently. Surprisingly, the vulnerability also affects OnionBrowser, an iOS app that enables browsing via the Tor anonymity network. The researchers who discovered the flaw suggest that the issue arises due to the implementation of passkeys. Passkeys facilitate authentication through an out-of-band connection, separate from Private Relay.
Researchers have created a site to help users determine if they are affected, which they reported to Apple. Despite Apple's lack of a timeline for a fix and their unwillingness to disclose a specific resolution time, they did permit the disclosure of the vulnerability. This incident marks the second time a flaw has impacted Apple's paid privacy features, both of which are part of the iCloud+ subscription.
While Apple addressed the Hide My Email flaw shortly after its discovery, a second, unaddressed flaw casts a shadow on the company's commitment to privacy and security.
Written by urgent.news from Six Colors's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.