Urgent.News

What's breaking now, across thousands of outlets.

Tech

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Apple's iCloud Private Relay, a feature designed to protect user privacy on Safari with paid iCloud+ plans, has revealed a significant flaw. According to researchers Talal Haj Bakry and Tommy Mysk, attackers can potentially uncover a user's real IP address through three WebKit features: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport.

WebKit forms the basis of Safari, and it's used in most iOS browsers. Private Relay works by encrypting traffic and routing it through two relays, separating the user's IP address from the sites they visit, but it doesn't tunnel every connection at the operating system level.

The most serious issue arises from WebAuthn, the standard behind passkeys. A webpage can trigger a Related Origin Request that Apple's credential service fetches directly from the device, bypassing Safari. This means the real IP address is sent to the destination server, all without any notification to the user. This flaw has been present since iOS 18. Additionally, DNS prefetching (introduced in iOS 26) and WebTransport (added in iOS 26.4) can also expose the user's real DNS servers and IP address, respectively.

The researchers demonstrated that a proof-of-concept site could reveal an IP address that Private Relay is supposed to mask. Interestingly, these WebKit flaws also impact proxy-based privacy browsers like Psylo and Onion Browser. Psylo 1.3.1 already blocks DNS-prefetch hints and disables WebTransport and WebAuthn by default, but it cannot control these new vulnerabilities.

Onion Browser's Silver security level already disables WebTransport, but the other issues remain outside its developers' control. Both researchers contacted the Tor Project and Onion Browser's developers after their discovery. They also submitted their findings to Apple, which promptly updated the report to indicate that they plan to address the issue, with a fix expected in fall 2026.

Apple separately acknowledged the incident and stated they are investigating the issue. This situation adds to Apple's recent challenges with its paid privacy tools, following a flaw in Hide My Email that exposed the real addresses behind supposedly anonymous aliases, which Apple fixed shortly after being notified.

Written by urgent.news from TechSpot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at thehackernews.com →

More in Tech

More from Thursday 6 August →