[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftqAlGuHECAh-u064HkJl1CwQu_UpN4yOAOzLlorR4wQ":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"22a5025b-e6bc-4fa2-8192-65d79c8d14db","Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses","apple-icloud-private-relay-can-expose-real-ips-through-webkit-proxy-bypasses-73f30e","Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from","Researchers Talal Haj Bakry and Tommy Mysk disclosed that Apple's iCloud Private Relay feature can leak users' real IP addresses through three WebKit vulnerabilities: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. These features bypass the configured proxy and send traffic directly from the device, exposing the user's true IP even when Private Relay is enabled. The issue affects Safari, all iOS\u002FiPadOS browsers, and macOS, with a proof-of-concept website available to test for leaks.","Apple's iCloud Private Relay can expose real IP via WebKit proxy bypasses in DNS, WebAuthn, and WebTransport.","Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses Ravie LakshmananAug 06, 2026Vulnerability \u002F Network Security Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from and what sites are being visited. It's available as part of the iCloud+ subscription. Researchers Talal Haj Bakry and Tommy Mysk, who found the issue, said the problem is rooted in three features in Apple's WebKit: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. WebKit is the default web browser engine used by Safari and all third-party browsers on iOS and iPadOS, such as Google Chrome, Microsoft Edge, Mozilla Firefox, Brave, and others. The three features \"bypass the configured proxy and send traffic directly from the device, which exposes the user's real network,\" the researchers said. \"The same leaks also affect Apple's iCloud Private Relay.\" The issues also affect macOS, as well as any other WebKit-based browser that relies on WebKit's proxy configuration APIs. In each of these cases, the device's actual IP address is leaked - DNS prefetching, which resolves hostnames through the device's normal DNS path instead of the proxy set by the browser WebAuthn Related Origin Requests, which make the operating system's credential service fetch a validation file directly from the device WebTransport, which opens a direct HTTP\u002F3 connection and bypasses the proxy Given that WebAuthn lets users log into websites using passkeys, any website that claims to support the web standard can view a user's real IP address even if iCloud Private Relay is on. \"Any website can configure WebAuthn (the API used for passkeys) in a way that causes WebKit to reveal the browser's real IP address, bypassing both proxy configurations and iCloud Private Relay in Safari,\" Mysk told The Hacker News. \"Because of the nature of the bug, the website has to deliberately exploit it to associate the user's current browsing session with the leaked IP address. This does not require any user interaction or the use of passkeys.\" A proof-of-concept (PoC) website named \"leaks.psylo[.]app\" has been made available for anyone to check if their real IP address leaks, even when Private Relay is on. While the \"HTTPS Traffic\" section refers to the regular network traffic that WebKit generates when connecting to a website, \"Possible IP leaks\" shows how the device's real IP address can leak out of the configured proxy path. \"We use the term 'possible' because not every browser is affected (for example, desktop Chrome is not), and the leaks are also mitigated when the user is connected to a VPN,\" Mysk added. Apple did not immediately respond to a request for comment. But the company told 404 Media that it's investigating the researchers' report. This is not the first time security issues have been discovered in iCloud Private Relay. Shortly after the feature was released in 2021, FingerprintJS highlighted a WebRTC-based mechanism that leaked a client's real IP address. The disclosure comes a little over a month after Cupertino addressed another vulnerability in its Hide My Email service that enabled users' real email addresses to be unmasked under certain conditions, undermining the feature's privacy guarantees. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Apple, Authentication Security, browser security, ios security, MacOS, mobile security, network security, Privacy, Vulnerability, Web Security ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions Download the 5-Step Action Plan for AI-Speed Exploitation Get the Checklist for Gaining Control of AI Use Across Your Organization Get the 2026 CISO Benchmark Report Based on 600 Security Leaders","https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fwebkit-proxy-bypasses-can-expose-real.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEi53VbynsVNPTCihg9qrqybX7Yu90yM3Tm7KlJnJCHz2_MOUQPyJys1uK6H5QkVqxGekck8qe-pA55tcy19IDYQ4_ndOKasvoaFiPJCI_NJClfHv6G14Ga5P_FPr0zyNijjRMBM-GBlt-XYRqCGAcrZxm9ETsAAu4kPh829ZKABQonHDlx2GuWG9-B-V383\u002Fs1600\u002Fapple-relay.jpg","2026-08-06T11:33:08+00:00","2026-08-06T14:00:22.071731+00:00",8,[18,21,23,25,28,31],{"name":19,"type":20},"iCloud Private Relay","product",{"name":22,"type":20},"WebKit",{"name":24,"type":20},"Safari",{"name":26,"type":27},"Apple","vendor",{"name":29,"type":30},"Talal Haj Bakry","threat_actor",{"name":32,"type":30},"Tommy Mysk","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,44,49],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":50},{"id":51,"icon":35,"name":52,"slug":53},"c70f3a41-2f0c-4608-870d-b8cbcd8be076","Cloud Security","cloud-security",[55],{"type":56,"value":57,"context":58},"domain","leaks.psylo.app","Proof-of-concept website to test for real IP address leaks from iCloud Private Relay bypass"]