Apple: Apple's Private Relay tool can leak users' IP addresses — with OnionBrowser also affected

Apple: Apple's Private Relay tool can leak users' IP addresses — with OnionBrowser also affected

Apple’s iCloud Private Relay Flaws Expose Real IP Addresses Despite Privacy Protections

Security researchers Talal Haj Bakry and Tommy Mysk have uncovered three critical flaws in Apple’s WebKit engine that bypass iCloud Private Relay, leaking users’ real IP addresses. The vulnerabilities affecting all Apple ecosystem browsers stem from DNS prefetching, WebAuthn origin requests, and WebTransport, which circumvent proxy settings to expose device-level traffic.

  • DNS Prefetching: Resolves hostnames via the device’s default DNS path, revealing the user’s actual DNS servers instead of the proxy’s (present since iOS 26.0).
  • WebAuthn Origin Requests: Forces the OS’s credential service to fetch validation files directly, exposing the real IP (introduced in iOS 18.0).
  • WebTransport: Establishes a direct HTTP/3 connection, bypassing the proxy (added in iOS 26.4).

iCloud Private Relay, a paid iCloud+ feature, is designed to mask IP addresses and encrypt Safari traffic but unlike a VPN, it only covers browser activity. Since WebKit powers all Apple browsers, the flaws impact the entire ecosystem. While alternative browsers like Tor and Mysk’s Psylo have released fixes, Apple has not confirmed a patch, though it is reviewing the report.

The researchers created a testing site to verify whether Private Relay is functioning correctly or still leaking IPs. The discovery highlights persistent risks in Apple’s privacy tools, even for users relying on built-in protections.

Source: https://www.techradar.com/pro/security/apples-private-relay-tool-can-leak-users-ip-addresses-with-onionbrowser-also-affected

Apple TPRM report: https://www.rankiteo.com/company/appleinsider

"id": "app1786019390",
"linkid": "appleinsider",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'iCloud+ subscribers using '
                                              'iCloud Private Relay',
                        'industry': 'Consumer Electronics, Software, Services',
                        'location': 'Cupertino, California, USA',
                        'name': 'Apple Inc.',
                        'size': 'Large (Fortune 500)',
                        'type': 'Technology Company'}],
 'attack_vector': 'Exploitation of WebKit engine flaws (DNS prefetching, '
                  'WebAuthn origin requests, WebTransport)',
 'customer_advisories': 'Users advised to verify iCloud Private Relay '
                        "functionality via researchers' testing site.",
 'data_breach': {'personally_identifiable_information': 'IP addresses '
                                                        '(indirectly)',
                 'sensitivity_of_data': 'High (geolocation and device '
                                        'identification)',
                 'type_of_data_compromised': 'IP addresses'},
 'description': 'Security researchers Talal Haj Bakry and Tommy Mysk have '
                'uncovered three critical flaws in Apple’s WebKit engine that '
                'bypass iCloud Private Relay, leaking users’ real IP '
                'addresses. The vulnerabilities affecting all Apple ecosystem '
                'browsers stem from DNS prefetching, WebAuthn origin requests, '
                'and WebTransport, which circumvent proxy settings to expose '
                'device-level traffic.',
 'impact': {'brand_reputation_impact': 'Potential erosion of trust in Apple’s '
                                       'privacy tools',
            'data_compromised': "Users' real IP addresses",
            'identity_theft_risk': 'Increased risk due to IP address exposure',
            'systems_affected': 'All Apple ecosystem browsers (Safari, etc.)'},
 'investigation_status': 'Under review by Apple',
 'lessons_learned': 'Persistent risks in privacy tools even with built-in '
                    'protections; need for independent security audits of '
                    'critical privacy features.',
 'post_incident_analysis': {'corrective_actions': 'Apple reviewing the report; '
                                                  'potential future patches '
                                                  'for WebKit and iCloud '
                                                  'Private Relay',
                            'root_causes': 'Flaws in WebKit engine (DNS '
                                           'prefetching, WebAuthn origin '
                                           'requests, WebTransport) bypassing '
                                           'proxy settings'},
 'recommendations': 'Users should consider alternative privacy-focused '
                    'browsers (e.g., Tor, Psylo) until Apple patches the '
                    'vulnerabilities. Apple should prioritize fixing WebKit '
                    'flaws and conduct thorough security reviews of iCloud '
                    'Private Relay.',
 'references': [{'source': 'Research by Talal Haj Bakry and Tommy Mysk'}],
 'response': {'communication_strategy': 'Public disclosure by researchers; '
                                        'Apple reviewing the report'},
 'title': 'Apple’s iCloud Private Relay Flaws Expose Real IP Addresses Despite '
          'Privacy Protections',
 'type': 'Privacy Bypass',
 'vulnerability_exploited': ['DNS prefetching',
                             'WebAuthn origin requests',
                             'WebTransport']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.