Security Researchers Find iCloud Private Relay IP Leak
Security researchers Tommy Mysk and Talal Haj Bakry discovered a vulnerability in iCloud Private Relay that leaks users' real IP addresses to websites.
Security researchers Tommy Mysk and Talal Haj Bakry discovered a vulnerability in Apple's iCloud Private Relay that allows websites to identify a user's real IP address. The flaw originates in the WebKit engine's handling of passkeys, DNS prefetching, and WebTransport, which enables requests to bypass the proxy path and send data directly from the device. This vulnerability affects all iOS browsers utilizing WebKit, including the OnionBrowser.
The Tor Project described the situation as "dire" but has not provided a timeline for a fix. In response to the leak, Mysk developed Psylo, a private browser that includes mitigations against these specific IP leaks. Mysk expressed hesitation regarding Apple's reporting process, citing previous experiences with inconsistent communication and delays.
Apple has indicated it plans to address the issue in Fall 2026. The flaw essentially allows any website that supports or simulates passkey support to uncover a user's actual IP address even when the iCloud Private Relay privacy feature is active.