Researchers Find WebKit Bugs That Can Leak Real IP Through iCloud Private Relay
Security researchers uncovered three WebKit functions that can bypass iCloud Private Relay, potentially exposing a user’s actual IP address or DNS details.
Security analysts Talal Haj Bakry and Tommy Mysk discovered that Apple’s iCloud Private Relay, designed to hide a Safari user’s IP and location, can be bypassed by three legitimate WebKit mechanisms. DNS prefetching may route lookups through the device’s native DNS path, leaking network information; a WebAuthn verification request used for passkey compatibility can expose the true IP address; and WebTransport can open a direct low-latency connection that also sidesteps the proxy.
These behaviors have been present on iOS since version 26.0 and on macOS, while VPNs remain unaffected because they operate at the system level. Apple has not responded to inquiries about the issue. Users are advised to keep Private Relay enabled, apply OS updates promptly, and consider a full-device VPN if concealing their IP is critical. Browser developers such as Psylo have already patched the problem in their own software.
Why it matters
It reveals that a widely used privacy feature may unintentionally reveal users' network identities.
In this story
