VYPR
advisoryPublished Aug 6, 2026· 1 source

Apple iCloud Private Relay Flaws Expose User IP Addresses via WebKit

Flaws in Apple's WebKit, exploited through passkey features, can inadvertently reveal users' real IP addresses to websites, undermining iCloud Private Relay's privacy protections.

Researchers have uncovered significant vulnerabilities within Apple's WebKit browser engine that can compromise the privacy offered by iCloud Private Relay. These flaws allow websites to potentially expose a user's true IP address, a critical piece of information that Private Relay is designed to mask. The issue arises when users interact with passkey features, as certain requests made during this process bypass the secure routing mechanism of Private Relay.

Discovered by researchers Tommy Mysk and Talal Haj Bakry, and corroborated by analysts at 404media, the vulnerability stems from how WebKit handles passkey authentication. When a website initiates a passkey request using the WebAuthn standard, the device may make a separate network request that does not go through the Private Relay's proxy. This bypass allows the destination server to log the user's actual IP address, effectively negating the anonymity provided by the service.

This is not a case of active exploitation leading to device compromise, but rather an information leak that weakens privacy safeguards. An IP address can reveal a user's general location and internet service provider, and when combined with other data, can be used for user profiling. While not direct evidence of a breach or account takeover, the leak can assist malicious actors such as stalkers, advertisers, or targeted attackers in identifying and tracking users.

The implications extend beyond Safari browsing. The underlying WebKit behavior also affects other applications on iOS that rely on the engine, including the OnionBrowser app, which uses the Tor anonymity network. While the official Tor Browser remains unaffected, this discovery highlights how even specialized privacy tools can be impacted by underlying system vulnerabilities.

Apple has stated that it is investigating the report. However, until a fix is implemented, users are advised to exercise caution when visiting unfamiliar websites that request or mimic passkey support. Promptly applying Apple software updates remains a crucial step in mitigating security risks.

For users seeking a higher level of anonymity, it is recommended to avoid relying solely on iCloud Private Relay for comprehensive privacy. Instead, utilizing system-wide privacy tools or dedicated anonymity networks like Tor, through official clients, is advised. Organizations should also be aware that Private Relay does not prevent all IP-based logging from Safari sessions and should not treat detected addresses as definitive identity signals.

The researchers did not provide specific indicators of compromise (IoCs) such as malicious files or domains, as the vulnerability is related to an information leak rather than a direct exploit leading to malware. The focus remains on the privacy implications of IP address exposure through a feature intended to enhance user anonymity.

This incident underscores the importance of understanding the limitations of privacy features and the ongoing challenges in securing the complex ecosystem of web technologies. As passkey adoption grows, ensuring that associated privacy mechanisms are robust and free from such leaks will be paramount for maintaining user trust and online security.

Synthesized by Vypr AI