Security researchers Talal Haj Bakry and Tommy Mysk have identified three features within Apple's WebKit engine that can bypass proxy configurations, resulting in the exposure of users' real IP addresses and DNS servers. These issues affect WebKit-based browsers on iOS and macOS, including those used for proxy services and Apple's iCloud Private Relay.
The identified features are DNS prefetching (available since iOS 26.0), WebAuthn Related Origin Requests (available since iOS 18.0), and WebTransport (available since iOS 26.4). These features send traffic directly from the device, circumventing the intended proxy path.
The vulnerabilities directly impact Apple's iCloud Private Relay, an opt-in feature for iCloud+ subscribers designed to hide a user's IP address when browsing with Safari. Researchers demonstrated that websites can still determine a user's real IP address even with Private Relay active. This is particularly relevant for websites supporting passkeys, as the device makes an authentication request outside the browser, bypassing Private Relay.
Additionally, proxy browsers on iOS, such as OnionBrowser for Tor, are affected. These browsers rely on WebKit to route all web traffic through proxy servers, but the identified flaws allow direct connections that reveal the user's actual network information. Virtual Private Networks (VPNs) are not affected as they tunnel all device traffic at the system level.
DNS prefetching resolves hostnames through the device’s normal DNS path, revealing the user’s real DNS servers instead of the proxy’s. WebAuthn Related Origin Requests cause the operating system’s credential service to fetch a validation file directly from the device, exposing the real IP address. WebTransport opens a direct HTTP/3 connection, bypassing the proxy and also revealing the device’s real IP address.
Following the disclosure of these flaws, Apple is facing a class action lawsuit alleging false advertising and fraud regarding its iCloud Private Relay feature. The lawsuit claims Apple misrepresented the privacy protection offered by the service.
The researchers stated they did not report the issue to Apple directly, citing past experiences with delays and inconsistent communication from the company.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Apple is facing a class action lawsuit alleging false advertising and fraud regarding its iCloud Private Relay feature. Security researchers discovered a flaw where websites supporting passkeys can bypass Private Relay, exposing users' real IP addresses, even if the website only pretends to support passkeys. This lawsuit claims Apple misrepresented the privacy protection offered by iCloud Private Relay.
Cybersecurity researchers discovered a security flaw in Apple's iCloud Private Relay that can reveal a user's real IP address. This issue stems from specific WebKit features that bypass the privacy tool's proxy, impacting all WebKit-based browsers on iOS, iPadOS, and macOS.
Security researchers Talal Haj Bakry and Tommy Mysk discovered that Apple's Private Relay feature, intended to mask IP addresses, can leak them when using passkeys due to issues within WebKit. This vulnerability affects Safari and other iOS browsers, potentially compromising user privacy. Apple is investigating the report, but a fix may take time.
Security researchers discovered that Apple's iCloud Private Relay service can leak users' real IP addresses when passkeys are used, due to how WebKit handles these requests outside of the proxied path. This issue affects Safari and other browsers on iOS, including the Tor-based OnionBrowser, potentially compromising user privacy despite the service's intended function.
Researchers discovered flaws in Apple's Private Relay feature that allow a user's real IP address to be revealed, despite the feature's design to hide it. This vulnerability affects iCloud+ subscribers using Safari and undermines the privacy protection Private Relay is intended to provide.
Apple's iCloud Private Relay, intended to mask user IP addresses, is failing to do so due to issues in Apple's web browser engine, allowing websites to discover real IP addresses. This vulnerability affects users of iCloud+ and also impacts the OnionBrowser app for Tor on iOS, raising concerns about the effectiveness of Apple's privacy features.
Three WebKit features bypass proxy configurations in iOS and macOS browsers, leading to IP and DNS leaks. These vulnerabilities affect proxy browsers, including Tor browsers, and Apple's iCloud Private Relay, exposing users' real IP addresses and DNS servers.