LIVE Jack Sparrow’s Pirates 6 Return in Talks — Dinotopia’s Forgotten Trilogy: The Three Video Games Based CS2 EWC 2026: Vitality, Falcons, Spirit, NAVI and Hayden Panettiere, Kairi and Until Dawn Voice, Dies
Video Gaming

Apple’s iCloud Private Relay Leaks Real IP Addresses via WebKit Passkey Flaw

3 min read
Apple’s iCloud Private Relay Leaks Real IP Addresses via WebKit Passkey Flaw

Security researchers Tommy Mysk and Talal Haj Bakry, the developers behind the privacy-focused Psylo browser, have disclosed three separate flaws in Apple’s WebKit browser engine that can expose a device’s real IP address and DNS servers even when iCloud Private Relay is turned on.

As we dug deeper, we found the source of the DNS leaks, plus two more leaks that actually reveal the device’s real IP address, all three living in WebKit, where they bypass the proxy settings provided by WKWebsiteDataStore.proxyConfigurations. The bugs were published in a technical write-up on the researchers’ blog on Tuesday, August 4, and were first reported by 404 Media.

iCloud Private Relay is a privacy tool bundled with Apple’s paid iCloud+ tier. Private Relay is only available to iCloud+ subscribers, and is not like a Virtual Private Network, or VPN, which protects someone’s IP address at the system level. Private Relay only works while using Safari. That narrow scope is exactly what the newly reported bugs exploit.

How the WebAuthn Passkey Flaw Exposes a Real IP

The most concerning of the three issues involves passkeys, the passwordless login standard built on WebAuthn. WebAuthn Related Origin Requests make the operating system’s credential service fetch a validation file directly from the device, which exposes the device’s real IP address, and this has been available since iOS 18.0. Because the request is handled by the OS rather than Safari, it never touches Private Relay’s proxy at all.

An attacker who wants to find someone’s protected IP can do so by setting up a website that uses WebAuthn, and there is no visible passkey prompt and no other indication that an IP address has been accessed in the background. In their own words, the researchers summarised the danger bluntly: “In short: any website that supports, or pretends to support, passkeys can see the user’s real IP address despite having iCloud Private Relay on.”

DNS Prefetching and WebTransport Add Two More Leak Paths

The passkey bug isn’t the only route to a real IP address. DNS prefetching resolves hostnames through the device’s normal DNS path, which reveals the user’s real DNS servers instead of the proxy’s, and has been available since iOS 26.0. WebTransport opens a direct HTTP/3 connection and bypasses the proxy, which also exposes the device’s real IP address, and has been available since iOS 26.4.

WebTransport shipped publicly in iOS 26.4, released in March 2026. All three mechanisms were designed to speed up browsing, but together they undercut the very proxy protections Private Relay and third-party proxy browsers rely on.

Every WebKit Browser on iOS Is Affected, Including a Tor Browser

Because Apple mandates that every browser on iOS run on WebKit, the exposure isn’t limited to Safari. Because all web browsers on iOS have to use Apple’s WebKit engine, the researchers also found the issues impact at least one Tor browser, called OnionBrowser.

Sources

More Video Gaming

From the Archive

Join the Conversation

Your email address will not be published. Required fields are marked *