Updated
Updated · The Hacker News · Aug 6
Apple iCloud Private Relay Leaks Real IPs via 3 WebKit Bypasses as Apple Investigates
Updated
Updated · The Hacker News · Aug 6

Apple iCloud Private Relay Leaks Real IPs via 3 WebKit Bypasses as Apple Investigates

3 articles · Updated · The Hacker News · Aug 6

Summary

  • Researchers Talal Haj Bakry and Tommy Mysk said iCloud Private Relay can expose a user’s real IP address because three WebKit features send traffic directly from the device instead of through Apple’s dual-hop relays.
  • The bypasses involve DNS prefetching, WebAuthn related-origin requests and WebTransport; the WebAuthn path is especially broad because any site can deliberately trigger the leak without user interaction or passkey use.
  • WebKit underpins Safari and all iOS and iPadOS browsers, so the issue also reaches macOS and other WebKit-based apps that rely on its proxy APIs, though desktop Chrome is not affected and VPNs can mitigate the leaks.
  • Apple told 404 Media it is investigating the report, while the researchers published a proof-of-concept site to let users test whether Private Relay is leaking their actual IP address.
  • The disclosure adds to earlier privacy cracks in Apple’s paid protections, following a 2021 WebRTC-based Private Relay leak and a Hide My Email flaw fixed a little over a month ago.

Insights

Could Apple's strict browser rules be the very thing exposing your private data to the world?
Why did security researchers intentionally withhold a major iPhone privacy flaw from Apple?