HeadlinesBriefing favicon HeadlinesBriefing.com

iCloud Private Relay IP Address Leak

MacRumors •
×

Security researchers Tommy Mysk and Talal Haj Bakry have discovered that Apple's iCloud Private Relay, a paid feature designed to mask users' IP addresses in Safari, can inadvertently expose real IP addresses to websites using or simulating passkeys. The vulnerability stems from how WebKit handles WebAuthn ceremonies, which are passed to the operating system's credential service. This service bypasses Private Relay and makes requests directly from the device, revealing the user's actual IP address to the destination server.

An attacker could exploit this by setting up a website that uses WebAuthn, potentially accessing a user's IP address without any visible prompt or indication. The researchers also identified that iOS 26's DNS prefetching and iOS 26.4's WebTransport feature can leak DNS server and IP address information, respectively. Apple has stated it is investigating these findings. Mysk and Haj Bakry have created a website to test for these leaks, noting that the issue affects some third-party browsers as well. For enhanced protection, users may consider using a VPN.