Apple iCloud Private Relay WebKit Flaws Leak Users’ Real IP Addresses
3 min read
Apple users who rely on iCloud Private Relay to conceal their online location may not be getting the protection they expect.
Newly disclosed flaws in WebKit, the browser engine used across iOS, can allow a website to see a visitor’s real IP address. The exposure weakens a privacy safeguard.
The issue can be triggered when a site supports, or merely claims to support, passkeys. A device may make a separate network request during sign-in, outside the protected browser route. That creates an opening for a malicious site to collect the address.
Researchers Tommy Mysk and Talal Haj Bakry identified the problem, and analysts at 404media verified that the test page returned a supposedly protected user’s real IP address.
404media said in a report shared with Cyber Security News (CSN) that the findings affect the privacy path. Apple said it is investigating the report.
The disclosure matters because an IP address can reveal a user’s network provider and rough location, and can be combined with other data for profiling.
It is not evidence that devices were infected or accounts were taken over. Readers following recent WebKit security concerns should note that this case is an information leak.
Apple iCloud Private Relay WebKit Flaws
Private Relay is intended to mask an iCloud+ subscriber’s IP address while browsing in Safari. Unlike a full-device virtual private network, it does not route every application’s traffic through the same protected connection.
That limited design becomes important when a request is made by another part of the operating system.
According to the researchers, passkey activity using the WebAuthn standard can call the operating system’s credential service instead of Safari.
Since that request does not enter Private Relay’s proxy route, the destination server receives the device’s real IP address. The user may only see a normal passkey prompt.
A malicious operator could build a page around a passkey check and log visitors’ addresses.
The technique does not require a victim to install software, open a document, or surrender a password. It only depends on visiting a site and interacting with a passkey feature, which makes clear browser-based privacy protections especially important.
This is separate from actively exploited WebKit zero days, where crafted web content can be used to compromise a device. Here, the reported risk is loss of anonymity.
Even so, an address leak can help a stalker, advertiser, fraud group, or targeted attacker narrow down who is behind a browsing session.
Impact on Anonymous Browsing
The researchers also found that the underlying WebKit behavior affects OnionBrowser, an iOS application that uses the Tor anonymity network.
Since iOS browsers must use WebKit, an app can inherit limitations beyond its own privacy design.
OnionBrowser creator Mike Tigas described two of the leaks as being in Apple’s control, while saying a third does not affect the app under its default configuration.
The official Tor Browser from the Tor Project is not affected by this reported issue, according to the source material, and remains the recommended way to use that network.
Users who need stronger anonymity should avoid treating Private Relay as a replacement for a system-wide privacy tool.
Related reporting on iCloud data access risks shows why privacy controls should be assessed by their limits, not their labels.
Until a fix is available, users can be careful with unfamiliar websites that request or imitate passkey support, particularly when privacy is essential.
They should apply Apple updates promptly and use the official Tor Browser on supported platforms when Tor-level anonymity is required. Keeping up with Apple privacy flaw fixes can help users judge when new protections are available.
Organizations should not assume that Private Relay prevents all IP-based logging from Safari sessions.
Site owners should avoid treating a detected address as a reliable identity signal, while security teams can review passkey flows and privacy claims.
The report describes no malicious files, domains, hashes, or other indicators of compromise, so no IoC table is included.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Apple iCloud Private Relay WebKit Flaws Leak Users’ Real IP Addresses appeared first on Cyber Security News.
Kaynak: Cyber Security News
Yayin Tarihi: 06.08.2026 04:49