Apple iCloud Private Relay WebKit Flaws Expose User IP Addresses
Key Takeaways Apple’s iCloud Private Relay, designed to mask user IP addresses, has been found vulnerable to information leakage. Flaws in WebKit, the underlying browser engine for iOS, can...
Key Takeaways
- Apple’s iCloud Private Relay, designed to mask user IP addresses, has been found vulnerable to information leakage.
- Flaws in WebKit, the underlying browser engine for iOS, can allow websites to bypass Private Relay and expose a user’s real IP address.
- The vulnerability is triggered when a website supports or simulates passkey authentication, prompting a network request outside the protected browser route.
- While not a device compromise, this issue undermines user anonymity, potentially exposing location and network provider data.
- Apple is reportedly investigating the findings, but no patch is currently available.
Apple iCloud Private Relay WebKit Flaws Expose User IP Addresses
Apple users who depend on iCloud Private Relay to safeguard their online anonymity may find their privacy expectations unmet. Recently discovered vulnerabilities within WebKit, the core browser engine that powers all iOS applications, can enable malicious websites to ascertain a user’s true IP address, effectively nullifying a key privacy feature.
Table Of Content
The exposure arises from a specific interaction: when a website either genuinely supports passkeys or merely mimics their functionality. During the sign-in process, this scenario can provoke a separate network request from the device, one that bypasses the typically protected browser channel. This creates a critical window for an adversary to capture the user’s IP address.
Security researchers Tommy Mysk and Talal Haj Bakry were instrumental in uncovering this problem. Their findings were subsequently validated by analysts at 404media in a report, confirming that a test page successfully retrieved the actual IP address of a user supposedly shielded by Private Relay. The report underscored that these findings directly impact the privacy assurances of iCloud Private Relay. Apple has acknowledged the report and stated it is under investigation.
The significance of this disclosure is considerable, as an IP address can reveal sensitive user information, including their internet service provider and general geographic location. This data can then be correlated with other digital footprints to construct detailed user profiles. It is important to note that this issue constitutes an information leak, not evidence of device compromise or account takeover, distinguishing it from more severe, actively exploited WebKit zero-day vulnerabilities where crafted web content can lead to device control.
How the Flaw Bypasses Privacy Protections
iCloud Private Relay is designed to obfuscate an iCloud+ subscriber’s IP address when browsing in Safari. Crucially, its design differs from a full-device Virtual Private Network (VPN); it does not route all application traffic through its protected connection. This architectural limitation becomes a vulnerability point when certain operating system components initiate network requests outside Safari’s direct purview.
According to the researchers, activities involving passkeys, which leverage the WebAuthn standard, can trigger the operating system’s credential service instead of routing through Safari. Because these requests do not pass through Private Relay’s proxy, the destination server receives the device’s unmasked IP address. The user, meanwhile, might only observe a standard passkey prompt, unaware of the underlying privacy bypass.
An attacker could craft a web page that integrates a passkey check, then silently log the IP addresses of visiting users. This method requires no software installation, document opening, or password submission from the victim. It relies solely on a user visiting a malicious site and interacting with a passkey feature, highlighting the critical importance of robust browser-based privacy safeguards.
Unlike actively exploited WebKit zero-day vulnerabilities that permit device compromise, the current concern is a breach of anonymity. Nevertheless, an IP address leak can provide invaluable data for various malicious actors, including stalkers, advertisers, fraud organizations, or targeted attackers seeking to identify individuals behind specific browsing sessions.
Impact on Anonymous Browsing
The researchers further discovered that this fundamental WebKit behavior extends its impact to OnionBrowser, an iOS application designed to utilize the Tor anonymity network. Given that all iOS browsers are mandated to use WebKit, such applications can inherit underlying platform limitations, irrespective of their own privacy-centric design. Mike Tigas, the creator of OnionBrowser, noted that two of the identified leaks are under Apple’s control, while a third does not affect OnionBrowser in its default configuration.
It is important to clarify that the official Tor Browser, developed by the Tor Project, is not affected by this specific issue and remains the recommended tool for users requiring robust Tor network anonymity. Users prioritizing heightened privacy should refrain from considering Private Relay a complete substitute for comprehensive, system-wide privacy solutions.
Previous reports concerning iCloud data access risks underscore the necessity of evaluating privacy controls based on their actual limitations rather than their marketing labels. Until a definitive fix is deployed, users are advised to exercise caution with unfamiliar websites that either request or simulate passkey authentication, especially when privacy is paramount.
What You Should Do
- Update Your Devices: Promptly apply all available Apple updates to ensure you have the latest security patches, as these often address underlying browser engine vulnerabilities.
- Exercise Caution with Passkeys: Be wary of unfamiliar websites that request passkey authentication, particularly if you suspect their legitimacy or if absolute anonymity is required.
- Understand Private Relay’s Limitations: Recognize that iCloud Private Relay is not a full VPN and does not protect all network traffic from all applications. For system-wide anonymity, consider dedicated VPN services or the official Tor Browser.
- Use Official Tor Browser for Anonymity: If Tor-level anonymity is essential, rely on the official Tor Browser on supported platforms, as it is not affected by this specific WebKit flaw.
- Review Website Interaction: Be mindful of how you interact with websites, especially those requesting authentication, to minimize unintended information leakage.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.