Urgent.News

What's breaking now, across thousands of outlets.

Tech

Apple's iCloud Private Relay feature is leaking users' real IP addresses

The discovery comes from security researchers Talal Haj Bakry and Tommy Mysk, who found three WebKit features that bypass application-level proxy settings: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. WebKit underpins Safari and, in most countries, every other browser available on iOS. Read Entire Article

Apple's iCloud Private Relay feature is leaking users' real IP addresses

Apple's iCloud Private Relay, a feature designed to protect user privacy on Safari with paid iCloud+ plans, has revealed a significant flaw. According to researchers Talal Haj Bakry and Tommy Mysk, attackers can potentially uncover a user's real IP address through three WebKit features: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport.

WebKit forms the basis of Safari, and it's used in most iOS browsers. Private Relay works by encrypting traffic and routing it through two relays, separating the user's IP address from the sites they visit, but it doesn't tunnel every connection at the operating system level.

The most serious issue arises from WebAuthn, the standard behind passkeys. A webpage can trigger a Related Origin Request that Apple's credential service fetches directly from the device, bypassing Safari. This means the real IP address is sent to the destination server, all without any notification to the user. This flaw has been present since iOS 18. Additionally, DNS prefetching (introduced in iOS 26) and WebTransport (added in iOS 26.4) can also expose the user's real DNS servers and IP address, respectively.

The researchers demonstrated that a proof-of-concept site could reveal an IP address that Private Relay is supposed to mask. Interestingly, these WebKit flaws also impact proxy-based privacy browsers like Psylo and Onion Browser. Psylo 1.3.1 already blocks DNS-prefetch hints and disables WebTransport and WebAuthn by default, but it cannot control these new vulnerabilities.

Onion Browser's Silver security level already disables WebTransport, but the other issues remain outside its developers' control. Both researchers contacted the Tor Project and Onion Browser's developers after their discovery. They also submitted their findings to Apple, which promptly updated the report to indicate that they plan to address the issue, with a fix expected in fall 2026.

Apple separately acknowledged the incident and stated they are investigating the issue. This situation adds to Apple's recent challenges with its paid privacy tools, following a flaw in Hide My Email that exposed the real addresses behind supposedly anonymous aliases, which Apple fixed shortly after being notified.

Written by urgent.news from TechSpot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at techspot.com →

More in Tech

More from Thursday 6 August →