{"id":15226,"date":"2026-08-06T10:32:17","date_gmt":"2026-08-06T10:32:17","guid":{"rendered":"https:\/\/nile1.com\/en\/?p=15226"},"modified":"2026-08-06T10:32:24","modified_gmt":"2026-08-06T10:32:24","slug":"apple-webkit-vulnerability-exposes-real-ip-addresses-on-paid-icloud-private-relay","status":"publish","type":"post","link":"https:\/\/nile1.com\/en\/2026\/08\/06\/apple-webkit-vulnerability-exposes-real-ip-addresses-on-paid-icloud-private-relay\/","title":{"rendered":"Apple WebKit Vulnerability Exposes Real IP Addresses on Paid iCloud Private Relay"},"content":{"rendered":"<p>Security flaws discovered in <a href=\"https:\/\/nile1.com\/en\/2026\/08\/06\/apple-set-for-major-september-hardware-pivot-with-first-foldable-smartphone-and-delayed-base-model\/\" class=\"auto-internal-link\" title=\"Apple Set for Major September Hardware Pivot with First Foldable Smartphone and Delayed Base Model\">Apple Inc.<\/a>&#8216;s <a href=\"https:\/\/nile1.com\/en\/2026\/07\/28\/apple-issues-sweeping-security-patches-across-entire-operating-system-lineup\/\" class=\"auto-internal-link\" title=\"Apple Issues Sweeping Security Patches Across Entire Operating System Lineup\">WebKit<\/a> browser engine are exposing the real IP addresses of users using its paid iCloud Private Relay service and other privacy-focused iOS applications, security researchers revealed.<\/p>\n<p>The vulnerabilities allow web servers to bypass application-level proxy settings and extract real network identifiers without user interaction or prompts. The findings, published by security researchers Talal Haj Bakry and Tommy Mysk and verified through a proof-of-concept test by tech outlet <a href=\"https:\/\/nile1.com\/en\/2026\/08\/05\/sec-monitored-global-airline-travelers-without-warrants-through-commercial-database\/\" class=\"auto-internal-link\" title=\"SEC Monitored Global Airline Travelers Without Warrants Through Commercial Database\">404 Media<\/a>, affect Safari as well as third-party browsers operating on iOS.<\/p>\n<p>Apple has acknowledged the report and updated its internal tracking to indicate plans to fix the issue, targeting a fix for fall 2026. The Cupertino, California-based company separately confirmed to 404 Media that it is actively investigating the matter.<\/p>\n<p>At the center of the leak are three specific WebKit features: WebAuthn Related Origin Requests, DNS prefetching, and WebTransport. The most severe exposure stems from WebAuthn, the standard underlying passkey authentication. Since the release of <a href=\"https:\/\/nile1.com\/en\/2026\/08\/04\/apple-to-enable-cross-platform-copy-paste-between-iphones-and-windows-pcs-under-eu-mandate\/\" class=\"auto-internal-link\" title=\"Apple to Enable Cross-Platform Copy-Paste Between iPhones and Windows PCs Under EU Mandate\">iOS 18<\/a>, WebAuthn triggers credential requests directly from the device rather than routing them through Safari&#8217;s proxy layer, exposing the user&#8217;s origin IP address directly to destination servers in the background.<\/p>\n<p>Additional exposure channels were introduced in later software updates. DNS prefetching, available since iOS 26, leaks users&#8217; actual DNS server addresses. Meanwhile, WebTransport, introduced in iOS 26.4, establishes direct HTTP\/3 connections that bypass proxy shields entirely.<\/p>\n<p>Unlike traditional virtual private networks (VPNs) that encrypt all system-level traffic, iCloud Private Relay operates as a dual-hop proxy available to paid iCloud+ subscribers starting at $0.99 per month. Traffic leaving Safari is routed through two separate relays to split user identities from web destinations, a mechanism designed to prevent both Apple and network providers from tracking browsing behavior.<\/p>\n<p>The WebKit vulnerabilities extend beyond Apple&#8217;s native browser because Apple has historically mandated WebKit for all iOS web browsers. While recent regulatory shifts under the European Union&#8217;s Digital Markets Act have begun forcing Apple to allow alternative browser engines in Europe, WebKit remains the underlying foundation for iOS browsers globally.<\/p>\n<p>As a result, third-party privacy browsers relying on proxy mechanisms have also been compromised. Developers of Psylo issued version 1.3.1 to mitigate the risk by blocking DNS-prefetch hints and disabling WebTransport and WebAuthn by default. The Onion Browser, associated with the Tor ecosystem, neutralizes WebTransport leaks under its stricter &#8220;Silver&#8221; security setting, though developers noted other WebKit-level leaks remain outside their direct control.<\/p>\n<p>The discovery marks the second recent privacy vulnerability tied to Apple&#8217;s paid security suite. Last month, a security flaw in Apple&#8217;s Hide My Email feature was disclosed, showing that anonymous email aliases could expose users&#8217; actual email addresses\u2014a bug Apple patched shortly after public disclosure despite receiving private notifications more than a year prior.<\/p>\n<div class=\"related-news-box\">\n<h3 class=\"related-news-title\">Read also:<\/h3>\n<ul class=\"related_news_list\">\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/08\/06\/nintendo-revenue-tops-estimates-on-software-surge-and-tariff-refund-despite-switch-2-drop\/\">Nintendo Revenue Tops Estimates on Software Surge and Tariff Refund Despite Switch 2 Drop<\/a><\/li>\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/08\/06\/apple-set-for-major-september-hardware-pivot-with-first-foldable-smartphone-and-delayed-base-model\/\">Apple Set for Major September Hardware Pivot with First Foldable Smartphone and Delayed Base Model<\/a><\/li>\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/08\/06\/openai-forced-to-slow-research-after-rogue-ai-agents-coordinated-cyberattack\/\">OpenAI Forced to Slow Research After Rogue AI Agents Coordinated Cyberattack<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Security flaws discovered in Apple Inc.&#8216;s WebKit browser engine are exposing the real IP addresses of users using its paid iCloud Private Relay service and other privacy-focused iOS applications, security researchers revealed. The vulnerabilities allow web servers to bypass application-level proxy settings and extract real network identifiers without user interaction or prompts. The findings, published &hellip;<\/p>\n","protected":false},"author":1,"featured_media":15228,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[5],"tags":[8175,1360,17827,12308,17831,17834,17830,17828,17829,17832,13061,17833],"class_list":["post-15226","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-404-media","tag-apple-inc","tag-icloud-private-relay","tag-ios-18","tag-onion-browser","tag-psylo","tag-safari","tag-talal-haj-bakry","tag-tommy-mysk","tag-webauthn","tag-webkit","tag-webtransport"],"_links":{"self":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/15226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/comments?post=15226"}],"version-history":[{"count":2,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/15226\/revisions"}],"predecessor-version":[{"id":15229,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/15226\/revisions\/15229"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/media\/15228"}],"wp:attachment":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/media?parent=15226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/categories?post=15226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/tags?post=15226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}