- Cybersecurity researchers Talal Haj Bakry and Tommy Mysk disclosed a WebKit vulnerability that bypasses Apple’s iCloud Private Relay.
- Three specific features in WebKit—DNS prefetching, WebAuthn, and WebTransport—are responsible for exposing the user’s real IP address.
- The issue affects Safari and all third-party browsers on iOS, iPadOS, and macOS; Apple is currently investigating the report.
Cybersecurity researchers Talal Haj Bakry and Tommy Mysk disclosed a security issue with Apple’s iCloud Private Relay tool that can expose a user’s real IP address. The problem is rooted in three features in Apple’s WebKit browser engine, which is used by Safari and all third-party browsers on iOS and iPadOS.
iCloud Private Relay employs a dual-hop architecture to ensure users’ privacy by routing their traffic through two relays. The researchers said the three features “bypass the configured proxy and send traffic directly from the device, which exposes the user’s real network.”
The features causing the leak are DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. “Any website can configure WebAuthn in a way that causes WebKit to reveal the browser’s real IP address,” researcher Tommy Mysk explained.
The issues also affect macOS, as well as any other browser relying on WebKit’s proxy configuration APIs. A proof-of-concept website named “leaks.psylo[.]app” has been made available for anyone to check if their real IP address leaks.
Apple told 404 Media that it’s investigating the researchers’ report. This is not the first time security issues have been discovered in the feature, following a WebRTC-based leak in 2021 and a recent vulnerability in its Hide My Email service.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
